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COURSE: (TS//S I //NF ) OVSC1205 Special Training on FISA (Analytical) 
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Analytical version: 
(U) Welcome to OVSC1205 
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GRAPH IC/AV: Interface screen 
with highlights added to Home, 
Exit, Glossary, Back, Next, 
Slider, Audio, Replay, Start 

Text for Mouseovers 

Home returns the lesson to its first 

screen. 

Exit closes the browser window. 
Glossary button Opens the 
Glossary in a browser window. 



Analytical version: 

(TS//S I /NF) Welcome to the OVSC1205 Business Records (BR) and Pen Register Trap 
and Trace (PR/TT) FISA Training for Analytical Personnel 

Technical version: 

(TS//S I /NF) Welcome to the Business Records (BR) and Pen Register Trap and Trace 
(PR/TT) FISA Training for Technical Personnel 

(U) Hover your mouse over each of the highlighted items to preview its function 
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Back navigates backward through 
the topic screens. 

Next navigates forward through the 
topic screens. 

Screen Count Display Area The 

current screen number and the 
total number of screens for the 
current lesson display here. 
Animation Slider Bar A slider bar 
to fast forward and back up the 
animation. 

Mute Toggles the audio off or on. 
Replay Starts the animation and 
audio over from the beginning. 
Play/Pause Starts or pauses the 
animation and audio. 



For the Analytical Track audio file name OVSC_1205_M0_0010_A 

(TS//S I //NF) (OGC Attorney): Welcome to the OVSC1205 Business Records (BR) and Pen Register Trap and Trace (PR/TT) Foreign Intelligence 
Surveillance Act (FISA) Training Course for Analytical Personnel. The overall classification of this course is TOP SECRET//SI//NOFORN. 

(U) Before we begin, let's take a few minutes to become familiar with the training interface. Hover your mouse over each of the highlighted items to preview 
its function. 



For the Technical Track audio file name OVSC_1206_M0_0010_T 

(T3//S I //NF) (OGC Attorney): Welcome to the OVSC1206 Business Records (BR) and Pen Register Trap and Trace (PR/TT) Foreign Intelligence 
Surveillance Act (FISA) Training Course for Technical Personnel. The overall classification of this course is TOP SECRET//SI//NOFORN. 

(U) Before we begin, let's take a few minutes to become familiar with the training interface. Hover your mouse over each of the highlighted items to preview 
its function. 
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(U) Core Modules 

1 . (TG//G I //NI") Business Records (BR) and Pen Register Trap and Trace (PR/TT) Bulk 
Metadata Programs 

2. (TG//G I //NO BR and PR/TT Metadata 

3. (U) Establishing Reasonable Articulable Guspicion (RAG) 

4. (TS//S I //NF ) Access, Gharing, Dissemination, and Retention Under the BR and 
PR/TT FIGC Orders 

5. (U) The Analytical and Technical Work Roles 



ALT TAG: 
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For the Analytical Track 

6. (U) The Analytical Work Role 



For the Technical Track 

6. (U) The Technical Work Role 



(TS//S I //NF) (OGC Attorney): This course will take you on a road trip, and along our journey we will learn about various topics with respect to the BR and 
PR/TT Bulk Metadata Programs. The first part of this course consists of a set of five core modules including: 

1 . (TS//S I //NF ) Module 1 : Business Records (BR) and Pen Register Trap and Trace (PR/TT) Bulk Metadata Programs 

2. (TS//S I //NF ) Module 2: BR and PR/TT Metadata 

3. (U) Module 3: Establishing Reasonable Articulable Suspicion (RAS) 

4. ( TQ//G I //NF- ) Module 4: Access, Sharing, Dissemination, and Retention Under the BR and PR/TT FISC Orders, and 

5. (U) Module 5: The Analytical and Technical Work Roles 



(Insert the applicable Analytical or Technical Track paragraph here) 



For the Analytical Track audio file name OVSC_1 205_M0_0020_A 

(TS//S I //NF) Because you are in an analytical role, or you are supervising staff in an analytical role, Module 6 of this course is designed with content 
specific to your needs in support of the BR and PR/TT Bulk Metadata Programs. Those in a technical role, or supervising staff in a technical role, will 
complete a separate version of the course designed with content specific to their needs in support of the BR and PR/TT Bulk Metadata Programs. Upon 
completion of the modules, you will be required to successfully complete a final exam. Further instructions regarding the exam will be provided later in the 

course. 

For the Technical Track audio file name OVSC 1205 M0 0020 T 
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(TS//S I //NF) Because you are in a technical work role, or you are supervising staff in a technical work role, Module 6 of this course is designed with content 
specific to your needs in support of the BR and PR/TT Bulk Metadata Programs. Those in an analytical role, or supervising staff in an analytical role, will 
complete a separate version of the course designed with content specific to their needs in support of the BR and PR/TT Bulk Metadata Programs. Upon 
completion of the modules, you will be required to successfully complete a final exam. Further instructions regarding the exam will be provided later in this 
course. 
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(TG//0 I //Nr) (OGC Attorney): I would also like to take a moment to introduce myself, my name is Nancy, and I am one of the Attorneys in the National 
Security Agency (NSA) Office of General Counsel (OGC). I am your first tour guide on this road trip, and I will be introducing you to many of the concepts 
you will need to know as you support the BR and PR/TT Bulk Metadata Programs. Now, let's meet the other tour guides. 

(TS//S I //NF) (HMC Character): My name is Marvin, and I am one of the Homeland Mission Coordinators (or HMCs) in the CounterTerrorism (CT) 
Production Center. I will be introducing concepts related to establishing Reasonable Articulable Suspicion (or RAS), querying the metadata, and other 
topics pertinent to analytical and technical staff supporting the BR and PR/TT Programs. 

(TS//S I //NF) (SV Character): My name is John, and I work in the Signals Intelligence Directorate (or SID) Office of Oversight and Compliance (or SV). I will 
be discussing topics related to compliance aspects of the BR and PR/TT Programs. 

(TS//S I //N F) (Technical Character): My name is Diana, and I will be discussing topics specifically related to the technical support provided to all aspects of 
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the BR and PR/TT Programs. The essential support provided by the technical personnel enables all of the roles to perform their BR- and PR/TT-related 
work in compliance with applicable legal documents and relevant authorities. 
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(TS//S I //NF) (OGC Attorney): So let's get started on our road trip. 



TOP SECRET//COMINT//NOFORN 
Page 7 of 7 



TOP GHCRi:T//G I //NOrORN 



Version 17 (Final) 
Last Updated 09/07/11 
IncludesCAO Revi ew feedback 



COURSE: (TS//S I //NF) OVSC1205 Special Training on FISA (Analytical) 
COURSE: (TS//S I //NF) OVSC1206 Special Training on FISA (Technical) 
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(U) MODULE 1 

(TS//SI//NF ) Business Records (BR) and Pen Register Trap and Trace (PR/TT) Bulk 
Metadata Programs 

(U) This module will enable you to: 

• (TS//S I //NF) Identify the purpose of the BR and PR/TT Bulk Metadata Programs 

• (TS//S I //NF) Identify the Foreign Powers covered by the BR and PR/TT Foreign 
Intelligence Surveillance Court (FISC) Orders 

• (TS//S I //NF) Contrast the differences in the authorities granted between BR FISC 
Orders and PR/TT FISC Orders 

• (TS//S I //NF) Recognize the role of the Bulk Metadata Programs in the context of the 
broader set of SIG I NT authorities 



( T5//5 I //NF ) (OGC Attorney): During the first part of our road trip we will discuss the Business Records (BR) and Pen RegisterTrap and Trace (PR/TT) 
Bulk Metadata Programs at a high level. As we progress on our road trip, we will discuss various aspects of the authorities granted by the Foreign 
Intelligence Surveillance Court (FISC) which support the BR and PR/TT programs and the policies that NSA implements to provide reasonable assurance 
that we are compliant with these authorities. 
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(U) This module will enable you to: 

• ( TS//S I //NF ) Identify the purpose of the BR and PR/TT Bulk Metadata Programs 

• (TS//SI//NF) la^nWytiTe^^BForeign Powers covered by the BR and PRATT Foreign Intelligence Surveillance Court (FISC) Orders 

• (TS//SI//NF)( | in the authorities granted between BR FISC Orders and PR/TT FISC Orders 

• ( TS//S I //NF ) Recognize the role of the Bulk Metadata Programs in the context of the broader set of SIG I NT authorities 
Scroll over text for foreign powers: 

( TS//S I //NF ) Under the FISA statute, a foreign power can include "a group engaged in international terrorism or activities in preparation therefore. 
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( TS//S I //NF ) The purpose of the BR and PRATT Bulk Metadata Programs is to support 
the Counterterrorism mission. 

( TS//S I //NF ) Bulk metadata consists of "unselected" communications events, and the 
BR and PR/TT Bulk Metadata programs complement NSA's traditional selection-based 
intelligence collection. 



( T5//5 I //NF ) (OGC Attorney): The BR and PR/TT programs are supported by two special authorities granted by the FISC which permit NSA to obtain 
telephony and internet communications bulk metadata from U.S. -based telecommunications service providers. The authority was granted by the FISC in 
support of the Counterterrorism mission to permit NSA to I earn more about a terrorist target's communications, even those terrorists potentially 
located in the United States. 



( TS//S I //NF ) Bulk metadata consists of "unselected" communications events, and the BR and PR/TT Bulk Metadata Programs complement NSA's 
traditional selection-based intelligence collection. 

( TS//S I //NF ) As you can probably imagine, bulk internet and telephony metadata, acquired within the United States, contains information to, from, or about 
U.S. persons. Therefore, because there is unminimized U.S. person information included within this type of metadata, there are special rules and 
procedures we must follow when acquiring, processing, accessing, storing, sharing, and disseminating this information. This metadata is highly sensitive 
which is why we have this specialized training. 

( TS//S I //NF ) In this course we discuss the metadata we collect, how we collect it what we are permitted to do with it as well as other special rules and 
procedures we must follow. 
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( TS//S I //NF ) (OGC Attorney): To get started, lefs discuss the individual Bulk Metadata Programs. The BR Program pertains to the acquisition of telephony 
metadata. The associated FISC Order allows NSA to ask specific U.S. -based telecommunications service providers for their business records. The 
business records, also known as call detail records, contain information about phone calls. 



(T5//SI//NF 



ram and associated FISC Order permits the collection of bulk Internet communications metadata. 




( TS//S I //NF ) Under both these FISC orders, NSA is pr ohibited from acquiring com munications content. Under these Progra ms, NSA may not listen to 
phone calls, or collect the body or subject of an email IB The Bulk Metadata authorities permit theBJ 
about the communications. ^^^^^^^^^^^^^^^^B 



( TS//S I //NF ) In Module 2, we will explore how each type of metadata is obtained and what specific information each order permits NSA to collect. 
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( TS//S I //NF ) (OGC Attorney): Due to the sensitivity of the data and the desire to protect the privacy of U.S. persons, the FISC imposes restrictions on how 
we can touch the data. For the purposes of this course, by 'touch" we mean any activity where there is an opportunity to commit a violation with regards to 
the Orders governing these authorities. We recognize that it takes a very diverse team of individuals working to see that the data is properly acquired, 
routed, prepared, stored, then queried, shared and disseminated. From acquisition to dissemination, including management and compliance, if you play a 
role in enabling this data to be used for its intelligence value, we consider you to be someone who "touches" this data. 

( TS//5 I //NF ) NSA's goal is to provide reasonable assurance that we are complying with the law AND making the most of these authorities to support the 
counterberrorism mission and protect the United States. 
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( TS//S I //NF ) (OGC Attorney): BR and PR/TT are two separate orders issued by the FISC, though the general access, sharing, dissemination, and retention 
rules are the same for the two programs. Those similarities are why the training for both is covered in t his course. Additionally, both Orders target the same 
aroups. referred to in the Orders as the Foreign Powers. The Foreign Pow ers named in the orders are I 

| Both the BR and PR/TT prog 

Articulable Suspicion, or RAS, to gain approval to query the bulk metadata with an identifier. We will get into much more detail about these two topics in 
later modules. 
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( T5//5 I //NF ) (OGC Attorney): There are two high level differences between the Orders as well. Details of the differences will be addresse d in later modules, 
but at a basic level, the biggest difference between the two Programs is how the metadata is obtained. 




( TS//S I //NF ) The other point where the Bulk Metadata Programs differ is in the area of hop restrictions for contact chaining. This will be described in detail 
in Module 4, but for now it is important to know that according to the Orders the hop restrictions are different for the BR and PR/TT Programs. 
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( TS//S I //NF ) (OGC Attorney): NSA must reapply to the FISC every 90 days to continue operating under these authorities. This process allows for the 
Government to seek modifications and for the F ISC to update these authorities to reflect changes that may affect NSA's collection and handling of BR and 
PR/TT bulk metadata. It is also crucial that all factors associated with NSA's implementation of these programs are fully compliant with the FISC Orders 
and guidelines. 

( TS//S I //NF ) As new orders are issued, this training may be augmented to address significant changes. Your organization will notify you if or when 
additional training is necessary. Should you have questions, you are strongly encouraged to contact your manager, Counterterrorism (CT) Homeland 
Security Analysis Center (HSAC), Technology Directorate (TD) Compliance, SID Oversight and Compliance, or the Office of General Counsel (OGC) for 
assistance and guidance. 
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( T5//5 I //NF ) NSA may perform SIGINT functions under various FISA authorities to include: 

• NSA FISA 

• FBI FISA 

• FAA Section 702 

• FAA Section 704 

• FAA Section 705(b) 

( TS//S I //NF ) BR and PR/TT Bulk Metadata Programs provide analysts with another opportunity to gain unique 
collection on a target 

( TS//S I //NF ) By leveraging various collection authorities, analysts can fill existing knowledge gaps on their 
target 



( TS//S I //NF ) (OGC Attorney): Now that you have a better understanding of what the BR and PR/TT Bulk Metadata Programs are, you may be wondering 
where these programs fit in the context of the broader set of SIGINT authorities. 

( TS//S I //NF ) Recall from OVSC1100, the Overview of Signals Intelligence Authorities, that we learned that in addition to E.O. 12333, NSA may perform 
SIGINT functions under various FISA authorities to include NSA FISA, FBI FISA, FISA Amendments Act (FAA) Section 702, 704, and 705(b). While there 
are specific rules governing when and how these authorities may be applied, each of these authorities has the potential to provide a valuable and unique 
complement to our E.O. 12333 collection resources. Similarly, the BR and PR/TT Bulk Metadata Programs provide analysts with another opportunity to 
gain unique collection on a target By leveraging as many of these various collection authorities available to them as permitted, analysts can fill existing 
knowledge gaps on their target. 



( TS//S I //NF ) One prime example of how an analyst leveraged several of these collection authorities to close crucial knowledge gaps on a target occurred in 
Fall 2009, when a CT analyst pieced together information obtained from E.O. 12333, FAA 702, and BR FISA authorities to reveal a terrorist plot on the New 
York subway system, which was subsequentiy disrupted by the FBI. 
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( TS//S I //NF ) Similarities beh/ueen SPCMA and BR & PRATT 

• (TS//5 l //Nr) Both involve exclusively metadata 

• (TS//S I //NI~) Both allow for querying of U.S. person identifiers under specific circumstances 



(TS//SI//NF ) Differences betvueen SPCMA and BR & PRATT 



(TS//S I //NF) Source of the metadata 

o SPCMA procedures apply to metadata 

already lawfully collected under E.O. 

12333, NSA FISA, FBI FISA, FAA 702, 704, 

and 705(b) authorities 
o BR and PR/TT programs authorize the 

acquisition of unselected, bulk metadata 



(TS//S I //N0 To query the 
metadata: 

o SPCMA requires valid and 

documented foreign intelligence 

purpose 
o BR and PR/TT require RAS- 

approved identifier for a limited 

target set 



(TS//S I //NF) (OGC Attorney): It is also important to understand what the BR and PR/TT Bulk Metadata programs are not You may have heard of SPCMA - 
the Supplemental Procedures Governing Communications Metadata Analysis. They allow NSA to treat communications metadata differently than content in 
the course of the analysis of communications metadata already lawfully collected under E.O. 12333, NSA FISA, FBI FISA, FAA 70 2, 704, and 705(b) 
authorities. Specifically, given a valid and documented foreign intelligence purpose, these new procedures permit contact chaining, | 

^communications metadata identifier, irrespective of nationality or location, in order to follow or discover valid foreign intelligence 
targets. WhatSPCMA and the BR and PR/TT programs have in common, then, is that they both exclusively involve metadata, and allow for queries of 
identifiers belonging to U.S. persons. 



(TS//S I //NF) Unlike SPCMA, however, the BR and PR/TT Programs authorize the acquisition of unselected, bulk metadata. Because of the sensitivity of 
this metadata, it may only be queried with identifiers for which RAS exists to believe that the identifier is directly associated with the Foreign Powers 
specified in the Court Order granted by the FISC. You will learn much more about the RAS standard in Module 3. 
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(U) Knowledge checks in the travel journal 



(U) Knowledge Check 

1. ( TS//S I //NF ) What is the purpose of the BR and PR/TT Bulk Metadata Programs? 

a) (T5//S I //NF) To permit NSA to I earn more about a terrorist targets communications, even 
those terrorists potentially located in the United States 

b) ( TS//S I //NF ) To give NSA the authority to collect and analyze the content of foreign and domestic 
terrorist telecommunications traffic 

c) ( T5//S I //NF ) To enable NSA to more effectivel y collect and analyze telep hony and internet 
communications metadata associated with the| 

d) (U) All of the above 



2. (TS//S I //NF) The BR and PR/TT Bulk Metadata Programs enable NSA to query identifiers related to. 

a) All terrorists regardless of their affiliation and origin. ^^^^^^^^^^^ 

b) Terrorists/terrorist groups associated with| | Foreign Powers, I 

c) Any foreign intelligence target. ^^^^^^^^^^^^^^^ 

d) Terrorists/terrorist groups associated withB 



(U) (OGC Attorney): Let's make a few notes in our travel journal and check to see what you remember from this topic! 



ANSWERS: 

Question 1: ( TS//S I //NF ) Correct! The purpose of the BR and PR/TT Bulk Metadata Programs is to permit NSA to learn more about a terrorist target's 
communications, even those terrorists potentially located in the United States. 

( TS//S I //NF ) Incorrect. The correct answer is a). The purpose of the BR and PR/TT Bulk Metadata Programs is to permit NSA to learn more about a 
terrorist target's communications, even those terrorists potentially located in the United States. 

Quest ion 2 : ( TS//S I //NF ) Correct! The BR and PR/TT Bulk Metadata Programs enable NSA to query identifiers related to terrorists/terrorist groups who fall 
under B^Foreign PowersBJ 

(TS//G I //Nr) -Incorrect The correct answer is b). The BR and P R/TT Bulk Metadata Programs enable NSA to query identifiers related to terrorists/terrorist 
groups who fall under BB Foreign Powers| 
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(U) Knowledge Check 

3. ( T5//5 I //NF ) One of the differences between BR and PR/TT is that the 

records delivered by the telecommunications providers, while the 

live, streaming Internet communications. 

a) bulk metadata, PR/TT metadata 

b) PR/TT metadata, bulk metadata 

c) PR/TT metadata, BR metadata 

d) BR metadata, PR/TT metadata 



4. ( T5//S I //NF ) Which of the following is true of BR and PR/TT and not other authorities? 

a) ( TS//S I //NF ) In the BR and PR/TT authorities, NSA is authorized to obtain metadata in bulk from 
U.S. -based telecommunications service providers that may not be available from other collection 
sources, and NSA can only query that metadata for counter proliferation purposes. 

b) ( TS//S I //NF ) In the BR and PR/TT authorities, NSA is authorized to obtain content from U.S.- 
based telecommunications service providers that may not be available from other collection 
sources, and NSA can only query that content for counterberrorism purposes. 

c) ( TS//S I//NF ) In the BR and PR/TT authorities, NSA is authorized to obtain metadata in bulk 
from U.S. -based telecommunications service providers that may not be available from 
other collection sources, and NSA can only query that metadata for counterterrorism 
purposes. 

d) ( TS//S I //NF ) In the BR and PR/TT authorities, NSA is authorized to obtain metadata in bulk from 
foreign telecommunications service providers that may not be available from other collection 
sources, and NSA can query that intelligence for any foreign intelligence purpose. 



(No audio or transcript on this page) 



ANSWERS 
Question 3: 




(TS//S I //Nr) Incorrect. The correct answer is d). One of the differences between BR and PR/TT is that 



Question 4: (T-5 7/S I //NF ) Correct! In the BR and PR/TT authorities, NSA is authorized to obtain metadata in bulk from U.S.-based telecommunications 
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service providers that may not be available from other collection sources, and NSA can only query that metadata for counterterrorism purposes. 
( TS//5 I //NF ) Incorrect. The correct answer is c). In the BR and PR/TT authorities, NSA is authorized to obtain metadata in bulk from U.S. -based 
telecommunications service providers that may not be available from other collection sources, and NSA can only query that metadata for 
counterterrorism purposes. 
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(U) Review learning objectives in the travel 
journal 



(U //FOUO ) (OGC Attorney): Now that we have completed the first part of our road trip, you should be able to: 

• ( TS//S I //NF ) Identify the purp ose of the BR and PR/TT Bulk Metadata Programs 

• ( TS//S I //NF ) Identify the^^Foreign Powers covered by the BR and PR/TT Foreign Intelligence Surveillance Court (FISC) Orders 

• ( T5//S I //NF ) Contrast the differences in the authorities granted between BR FISC Orders and PR/TT FISC Orders 

• ( TS//S I //NF ) Recognize the role of the Bulk Metadata Programs in the context of the broader set of SIGINT authorities 
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(U) MODULE 2 

(TG//S I //ND BR and PR/TT Metadata 

(U) This module will enable you to: 

• ( TS//S I //NF ) Distinguish differences between BR and PR/TT metadata 

• (TG//G I //Nr) Recognize restrictions placed on BR and PR/TT metadata storage and retention by the 
BR and PR/TT Bulk Metadata Programs 



GRAPHIC/AV: 

(U) Present learning objectives in the travel 
journal 



(TG//G I //NH ) (OGC Attorney): During this part of our trip we discuss the BR and PR/TT metadata in greater detail. Specifically, we look at the metadata 
which may be obtained, how bulk metadata is collected under these authorities, and the storage restrictions with which NSA must comply. Other modules 
will address restrictions related to the dissemination and processing of the bulk metadata. 



(U) This module will enable you to: 

• (TG//G I //NT) Distinguish differences between BR and PR/TT metadata 

• (JS//5I//NP) Recognize restrictions placed on BR and PR/TT metadata storage and retention by the BR and PR/TT Bulk Metadata Programs 



(T5//G I //MF ) Note that other restrictions will be addressed in other modules. 



Derived From: NSA/CSSM 1-52 
Dated: 20070108 
Declassify On: 20350501 

TOP SCCRL"r//5 l //NOrORN 
Page 1 of 12 



TOP SCCRCT//5 l //NOrORN 



DATE/PREPARER: TAP 


Topic 

(T5//SI//NF) Differences Between 
BR and PR/TT Metadata 


Page Classification 

TOP 

□ ECRET//COMINT//NOFORN 


Screen Number 
2 of 11 


Home 


Exit Glossary Back Next 


FRAME ID: 2020 

NEXT FRAME ID: 2030 

BACK FRAME ID: 2010 
ALT TAG: 
GRAPHIC/AV: 

(U) Possible cutaway images may include: 
• Image depicting telephony and 
internet communications 




(T5//5I//ND (OGCAttomev)^neoftheke\ 
as as thej 


^ifference^be^veen BR and PR/TT metadata is the type of metadata that each OrdenDemTitsNSAtoobtain 
B This lesson will focus specifically on the kinds of metadata and| 





TOP SECR[IT//S I //NOrORN 
Page 2 of 12 



TOP 5ECR.[IT//S I //NOrOKN 



DATE/PREPARER: TAP 



Topic 

(T5//5 I //ND BR Bulk 
Metadata Program 



Home 



Page Classification 

-rep~ 

5 EC R ET//CO M l NT//NO FO R N 



Exit 



Glossary 



Screen Number 
3 of 11 



Back 



Next 



FRAME ID: 2030 



NEXT FRAME ID: 2040 



BACK FRAME ID: 2020 



ALT TAG: 



GRAPHIC/AV: 

(U) Possible cutaway images may include: 

• images pertinent to 

telecommunications and records, 
messaging such as billing 



(TS//SI//NF) These Business Records 
Include Examples Such As: 

• Originating and terminating telephone 
numbers 

• IMSI 

• IMEI 

• Trunk identifiers 

• Telephone calling card numbers 



(TG//5 I //Nr ) (OGC Attorney): Lets take a look at the BR Bulk Metadata Program. As we mentioned in Module 1, the BR Primary Order pertains specifically 
to telephony metadata which is kept by U.S. -based telecommunications companies as part of their normal business operations. They retain this 
information, in part, so they can send their subscribers a bill every month. 

(T5//S I //Nr) The business records include, for example, originating and terminating telephone numbers. International Mobile Subscriber Identity (IMSI), 
International Mobile Station Equipment Identity (IMEI), trunk identifiers, and telephone calling card numbers. 
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(TS//S I //NF) These Business 
Records Do Not Include: 

• Content of any communication 

• Name, address, or financial 
information of a subscriber or 
customer 



(TG//G I //Nr) (OGC Attorney): As you can imagine, NSA is interested in the same kinds of telephony information fori 



and contact chaining 
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(T5//5 I //NT ) (OGC Attorney): In the case of Internet communications, there are no easily accessible comparable business reco rds that could provide NSA 

with the kind of information in which we are interested. Subscrib ers do not receive a bill based on who thev email^^^^^^B I I rto acquire the b ulk 

metadata for internet communications, the FISC permits NSA to| 
PR/TT metadata and forward it back to NSA for analysis. 




rrS7/G I // ME4 As we discussed in Module 1, NSA is not permitted to collect communications content under either of these Orders, so 
|in such a way as to exclude content 1 
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(TG//G I //Nr) (OGC Attorney): The FISC goes into great detail in the Orders about many aspects of the collection to provide reasonable assurance that NSA 
is not overreaching its authority. 

(T5//S I //Nr) For example, FISC requirements t hat affect PR/ 

• Which U.S .- based telecommunications! 

• The specific! 

• The types ofl 

• Which specific! 
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(TG//G I //NT) (OGC Attorney): Both Orders mandate that the BR and PR/TT bulk metadata must be stored in repositories within secure networks under 
NSA's control. The methods for storing the results of approved queries of the bulk metadata w ill be explained in Module 4. BR and PR/TT bulk metadata 
may only be stored in authorized and specifically designated repositories. 



(TS//S I //NF) The FISC also requires NSA to mark and tag the BR and PR/TT metadata so that software and other control mechanisms may provide 
reasonable assurance that the information is only accessed by authorized personnel who have completed the required training and have the necessary 
credentials. 



(T5//5 I //NF) The bulk BR and PR/TT metadata coming into the repositories has an expiration date set by the FISC. NSA does not have the authority to 
maintain the unselected BR and PR/TT metadata indefinitely. The FISC permits NSA to maintain this metadata for 60 months from the date of collection at 
which time it must be destroyed. 
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1. (T5//5 I //Nr) Which of the following describe the BR Bulk Metadata Program: 

a) ( T5//5 I //Pvir) The BR Order pertains to telephony metadata which is kept by U.S. -based 
telecommunication companies. 

b) (T5//5 I //Nr) BR refers to Business Records which is information U.S. -based telecommunications 
companies already have in their possession and use as part of their normal business. 

c) (TD//G I //NO NSA uses Business Recordinformatior^uch as terminating telephone numbers, 
IMSI, IMEI and trunk identifiers forB Hcontact chaining analysis. 

d) (U) All of the above. 

2. (T5//5 I //Nr ) Which of the following does not describe the PR/TT Bulk Metadata Program? 

a) (TS//SI//NF) 

b) (TS//SI//NF) NSA only collects limited metadata from the communications of approved 
targets. 

c) ( TS//S I //NP NSA collects specific categories of metadata to include the 'to," 'from," "cc," and 
"bcc" lines of an email. 

d) (U) None of the above. 

4 Which of the following statements is true? 

a) ( T5//5 I //NF ) Bulk BR and PR/TT metadata may not be kept for longer than 48 months. 

b) (T5//5 I //NF) Non-U. S. person metadata may be kept at NSA indefinitely. 

c) (TG//S I //Nr) The bulk metadata is tagged to provide reasonable assurance that the data is 
only accessed by authorized personnel. 

d) (U) All of the above. 

e) (U) None of the above. 



(U) (OGC Attorney): Let's check what you remember from this topic! 



ANSWERS: 

Question 1. ( TS//S I //Nr) Correct! All of the above describe the BR Bulk Metadata Program. 

(TS//SI//NF) Incorrect The correct answer is d). All of the above describe the BR Bulk Metadata Program. 



Question 2. (TS//5 I //I 
of approved targets. | 




from the communications 
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TTG//5 1 //NT )- Incorrect The correct answer is b) because it is NOTTRUE that for the PR/TT Bulk Metadata Program NSA only collects limited metadata 
from the communications of approved targets. 



Question 3. (TS//S I //NF ) Right! The bulk metadata is tagged to provide reasonable assurance that the data is only accessed by authorized personnel. 
(TG//G I //NO Incorrect. The correct answer is c). The bulk metadata is tagged to provide reasonable assurance that the data is only accessed by authorized 
personnel. 
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(U) Now that we have completed this part of your trip, you should be able to: 

• - (TS//3 I //NO Distinguish differences between BR and PRATT Bulk Metadata 

Programs 

• - (T S //S I //Nr -) Recognize restrictions placed on metadata storage and 
retention by the BR and PRATT Bulk Metadata Programs 



(U) (OGC Attorney): Now that we have completed this part of our trip, you should be able to: 

• (TS//G I //NO Distinguish differences between BR and PR/TT Bulk Metadata Programs 

• (TS//S I //NF) Recognize restrictions placed on metadata storage and retention by the BR and PR/TT Bulk Metadata Programs 



(TS//S I //NF) During the next portion of our trip, we will meet up with Marvin who will talk to us about the Reasonable Articulable Suspicion (RAS) standard 
and the requirements that must be met in order to query the bulk metadata. 
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(U) Module 3 

(U) Establishing Reasonable Articulable Suspicion (RAS) 

(U) This module will enable you to: 

• (TS//S I //Nr) Recognize the direct relationship between the Foreign Powers and 
establishing RAS 

• (T5//S I //NF) Identify the key components of RAS and how it is applied to candidate 
identifiers 

• (TS//S I //N F ) Identify who can adjudicate and approve a RAS nomination 

• (T5//5 I //Nr) Recognize the requirement associated with identifiers linked to U.S. 
persons - the OGC First Amendment Review 

• (TS//S I //MF ) List common sources of information used to construct a RAS 
nomination statement 



(TS//5 I //NF) (OGC Attorney): This part of our trip will provide you with an overview of the Reasonable Articulable Suspicion (RAS) Standard including 
definitions and descriptions to help you understand how to satisfy RAS and how to apply it to identifiers under the BR and PR/TT FISC Orders. In addition 
to this training, guidance is also outlined in a RAS memo that can be obtained from the Office of General Counsel. 

(T5//SI//NF) This module will enable you to: 

• tTS//SI//NT> Recognize the direct relationship between the Foreign Powers and establishing RAS 

• (TG//G I //Nr) Identify the key components of RAS and how it is applied to candidate identifiers 
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• (T5//G I //NO Identify who can adjudicate and approve a RAS nomination 

• (TG//S I //NO Recognize the requirement associated with identifiers linked to U.S. persons - the OGC First Amendment Review 

• (TS//5I//NF) List common sources of information used to construct a RAS nomination statement 

(TG//G I //NO At the conclusion of this module you should understand that an identifier must be RAS-approved before conducting a query. The topic of 
querying BR and PR/TT bulk metadata will be discussed in Module 4. 



TOP SECRET//S I //NOrORN 
Page 2 of 17 



TOP 5CCRCT//5 l //NOrORN 



DATE/PRE PAR ER: 11/09/2010 SLS 



Topic 

-CT5//SI//NO The Two 
Foreign Powers 



Home 



Page Classification 

I UP b EL R ET//CQ M l NT//NO TO R N ■ 



Exit 



Glossary 



Screen Number 
2 of 13 



Back 



Next 



FRAME ID: 3020 



NEXT FRAME ID: 3030 



BACK FRAME ID: 3010 



ALT TAG: 



GRAPHIC/AV: 

(U) Insert graphics/animations to illustrate 
the umbrella groups and their affiliated 
terrorist organizations 
(U) Add graphics to illustrate contact 
chaining, seeds, and hops. 



4TG//SI//NP) Who can be targeted under the BR and PRATT authorities? 




(TS//S I //NF) ThePjjForeign Powers named in these authorities a 



<TS//G I //Nr ) NSA is not permitted to query the BR and PRATT metadata unless there is a 
reasonable articulable suspicion that the identifier is associated with one of the F ISC- 
approved groups. 



tT5//G I //Nr- ) (OGC Attomev)^rheBRandPR^^^rderslisUDvn authority. T_ 

Foreign Powers areBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB The Orders detail \ 

NSA is not permitted to query the BR and PR/TT metadata unless there 
is a reasonable articulable suspicion that the identifier is associated with one of the F ISC-approved groups. 



(TG//G I //NO It is important to note that you cannot query using just a ny foreign intelligence target Furthermore, vou cannot query using just any terrorist 
JargetJrto^CAN however query using identifiers specifically linked to| 

las named in the Orders. Note that the lists may evolve and your target may be added or removed overtime, so you should reference the 
most current version of the lists for updates. 
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(TS//SI//NF) (OGC Attorney): The FISC recognizes the potential counterterrorism advantage gained through analysis of the BR and PR/TT bulk metadata; 
however, because there is a great deal of U.S. person information included in the bulk metadata, the FISC has set strict guidelines on when and how 
analysts can access the metadata under these authorities. The RAS standard is one of these guidelines which helps to provide reasonable assurance that 
only legitimate terrorism-related identifiers are used to query the bulk metadata. This standard must be met before queries can be conducted. 



(TS//S I //NF ) So what is RAS? RAS is a legal standard that describes the measure of proof required to support a decision whether to permit an identifier to 
be queried from the bulk metadata. The Reasonable Articulable Suspicion standard requires justthat-a suspicion that you can explain in a reasonable way. 
It does not require certainty, but is more concrete than a simple hunch. It may be easiest to think of it in terms of other standards with which you may be 
familiar. 



( I S//IJI//NI-) Many of you may be familiar with legal standards of proof applicable in other situations. It may be helpful to understand how the RAS standard 
compares to these other legal standards. For example, a jury in a criminal case will not convict an accused unless the evidence of guilt is "beyond a 
reasonable doubt. 'This is the highest legal standard of proof. A jury in a civil case (such as a personal injury case or a contract dispute) might award a 
plaintiff money damages if the plaintiff proves the elements of his claim by "a preponderance of the evidence. "This standard is lower than "beyond a 
reasonable doubt." Lower still is the standard of proof required to justify issuance of a search warrant - "probable cause" - whether that search warrant is 
for the suspect's home or the content of the suspect's communications. The RAS standard falls below "probable cause." 
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(T5//5 I //NF) The FISC has determined that this lower standard of proof is reasonable for the querying of metadata because communications metadata 
does not carry with it the same privacy protections as communications content The RAS standard falls below "probable cause" but above a mere hunch or 
guess. 
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(TS//G I //NT) An identifier will meet the Reasonable A rticul able Suspicion Standard if based on 

the factual and practi cal consi derati ons of everyday I i f e on whi ch reasonabl e and prudent 
persons act, there are facts giving rise to a reasonable articulable suspicion that the identifier is 
associated with one of the specified Foreign Powers." 

- Forei gn I ntel I i gence Survei 1 1 ance Court 



GRAPHIC/AV: 

(U) Continue to display definition of RAS 
then pull out the RAS Equation. 



RAS Equation 

Identifier + Link to Foreign Power = RAS 



(TS//SI//NF) (OGC Attorney): As it applies to the BR and PR/TT Orders, RAS is a suspicion that an identifiet^ucl^sanemai^ddressjele^ 
or other identifier type, is associated with one of the^H Foreign Powers named in BR and PR/TT Orders | (The 
F ISC requires that NSA base that suspicion on a certain level of factual evidence — and NSA must articulate those facts that connect the identifier with one 
of the named terrorist organizations. The requirement that these facts be articulable effectively provides reasonable assurance that analyst queries of the 
metadata are based on substantive information (meaning more than simple hunches or uninformed guesswork). So in order to obtain RAS approval for an 
identifier, analysts must provide enough factual evidence that it would lead a reasonable person to suspect that an identifier is associated with one of the 
named Foreign Powers in the BR and PR/TT Orders. We will get more into the kinds of facts that may be used and how they can support a RAS 
nomination later in this module. 



(T5//5I//Nr) In summary, based on the factual and practical considerations of everyday life 
determine if there is a reasonable articulable suspicion that the identifier is associated with [ 

(named in the Orders. There must be at least one qualifying fact giving rise to the suspicion that the identifier is associated 
with one of the Foreign Powers listed in the BR and PR/TT Orders. Unless that determination is made, the identifier cannot be approved to query this 
metadata repository. NSA's implementation of the BR and PR^TOrders mandates that the RAS nomination statement must clearly link the identifier/target 
to one of the Foreign Powers and documenl II u In n In n i n i^^^^^^B mil in 1 1 will be discussed later in the module. 
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(U) Analyst Level of Effort Required graphic 




(T5//SI//NF) (HMC Character): From an Anah 
BR and PR/TT and other SIGINT authorities, 
considered less than that required for FBI CT 


/sis and Production standpoint, lefs look at RAS in the context of the analyst level of effort required to utilize 
As the illustration shows, the level of effort required by an analyst to establish RAS would normally be 
FISA or FAA 704/705b, but it is more than what is needed to utilize E.O. 12333, for example. 



TOP 5CCRCT//5 l //NOrORN 
Page 7 of 17 



I UP SbLKb I //SI//NUI-UKN 



DATE/PRE PAR ER: 11/09/2010 SLS 



Topic 

(U) Who Can Make a RAS 
Determination? 



Home 



Page Classification 

I UP bbCRE T //COM I NT//NOFORN 



Exit 



Glossary 



Screen Number 
6 of 13 



Back 



Next 



FRAME ID: 3050 



(U) Who can make a RAS determination? 



NEXT FRAME ID: 3060 



BACK FRAME ID: 3040 



ALT TAG: 



GRAPHIC/AV: 



(U) Who can make a RAS determination? 

(U// FOUO) Homeland Mission Coordinators (HMCs) 

(U/ /rOUO ) Chief of the CT Homeland Security A neJysis Center 

(U/ /FOUO) Deputy Chief of the CT Homeland Security Analysis 
Center 

(U) No one else can make this determination! 



TTG//5I//NF-) (OGC Attorney): The FISC states that the RAS decision is based on considerations of "reasonable and prudent persons." This does not, 
however, mean that anyone can approve an identifier for RAS. There are a select number of people within NSA who have been given the authority to 
approve identifiers for querying under these two authorities. Those individuals are called Homeland Mission Coordinators or HMCs. 

( TG//5 I //Nr) (HMC Character): As was just mentioned, RAS determinations are typically made by specially trained personnel in the Office of 
Counterterrorism and its Extended Enterprise; these individuals are titled Homeland Mission Coordinators, typically abbreviated as HMCs. These 
individuals, like me, have been given special training on how to apply the RAS standard and how to apply it consistently. HMCs are specially trained 
individuals who have extensive experience working with this target set and who have extensive experience working with these authorities. The HMCs can 
take a RAS nomination, review the facts, and make a determination as to whether or not that particular identifier meets the RAS standard. 



(TS//S I //NT) (HMC Character): According to the BR and PR/TT Orders, in addition to the HMCs, the Chief and Deputy Chief of the Counterterrorism 
Homeland Security Analysis Center are authorized to make a RAS determination; although, it is generally the HMCs who make the RAS determinations. To 
reemphasize, no one else is authorized to make RAS determinations according to the Orders. 
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(TS//SI//NF) (HMC Character): There are certain identifiers that require an extra RAS review/approval step. As you might imagine, those are the identifiers 
that are reasonably believed to be used by U.S. persons. Why does this matter? It matters because the U.S. Government is forbidden from regarding a 
U.S. person as associated with a Foreign Power solely because he or she is exercising his or her First Amendment rights. 



(TG//G I //Nr) ( OGC Attorney): That's right. Any identifier believed to be used by a U.S. person must be forwarded to the OGC by a Homeland Mission 
Coordinator following his or her approval. An OGC attorney will review the RAS nomination, as well as the RAS decision made by the Homeland Mission 
Coordinator, and make a determination as to whether or not NSA is targeting that individual based solely on activities that are protected by the First 
Amendment to the Constitution. If there is any indication that the RAS is based solely on information or evidence protected somehow by the F irst 
Amendment, OGC will require additional information to support the RAS nomination. 

(TS//G I //NT ) (HMC Character): If you are an analyst should you abandon a RAS nomination if there is a potential First Amendment concern? Absolutely 
not. The presence of First Amendment evidence does not invalidate a RAS, it just cannot be the sole basis for a nomination. The OGC review is really 
transparent to the analyst, though it is a part of the process that you should be aware of. 
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(U) What sources of information can be used to justify RAS? 
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(T!y/a//Nr) Fl SA Orders 



Existi ng Fl SA Orders 



TT575I77NF* Reports and/or RAW 
SIGINT 

SIGINT reports 

F I SA survei 1 1 ance data deri ved from other 
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Raw SI Gl NT (after a Reporti ng Source 
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SIGDEV Work 
Other transcri pts 



(TG//5I//ND IC and Public Sector 

Federal Bureau of I nvestigation documents 
Central I ntel I i gence Agency documents 
National Counterterrorism Center 
documents 

Documents from other U.S. Government 

Organizations 

Foreign Partner nations 

Public records available on the 

internet, newspapers, or other public 

resources 



( I b//bl//Nh) (HMC Character): So now let's look at the type of evidence that can be used to justify RAS. NSA can use any information that is lawfully in our 
possession. A published SIGINT report describing the results of electronic surveillance of a target might be more reliable than say pocket litter found during 
a detainee's interrogation — but NSA can rely on any lawfully held evidence. The HMCs are responsible for assessing the quality and reliability of the 
evidence. 



(T5//5 I //Nr ) (OGC Attorney): Sources that are often used to justify a RAS nomination include, but are not limited to: 
Existing FISA Orders 
• SIGINT reports 

FISA surveillance data derived from other authorized targets 

SIGINT traffic, as long as the submitting analyst has performed a Reporting Source Validation Check 
SIGDEV work (with verified sources), and 
Other transcripts 




If an analyst/requestor uses unpublished query results in a RAS justific ation, and the y classify the material appropriately as 
then that information will only be visible to thoseB Husers with B HorB H credentials, as confirmed 
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(TS//SI//NF) (OGC Attorney): The following IC and public sector (open source) sources are also examples of sources that are frequently used: 
Federal Bureau of Investigation (FBI) documents 
Central Intelligence Agency (CIA) documents 
The National Counterterrorism Center (NCTC) documents 
Documents from other U.S. Government Organizations 
Foreign Partner nations, and 

Public records available on the internet, newspapers, or other public resources. 



TOP SECRET//G I //NOrOriN 
Page 11 of 17 



TOP SECRET//S I //NOrORN 



DATE/PRE PAR ER: 11/09/2010 SLS 



(U) 



Home 



Page Classification 

TOP 5ECRET//COM I NT//NQFORN 



Exit 



Glossary 



Screen Number 
9 of 13 



Back 



Next 



FRAME ID: 3080 



C T 5//S I //IMF) I 



NSA's RAS Identifier Management System 
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• (TG//G I //NT) Supports the Homeland Defense Counterterrorism (CT) Mission. 

• (TS//S I //NF ) Provides the ability to request, justify, review, approve/disapprove RAS 
nomi natio ns/requests . 

• (TS//G I //NT) Is the authoritative source for the list of RAS-approved identifiers and will export that list to 
other systems that require it 

• (TS//S I //NF ) Provides metrics and other information to facilitate oversight review and report generation for 
the Department of J ustice (DOJ ) and the FISC. 

(U) Time Bounded Approvals 



(T5//5 I //NO (HMC Character): Remember from earlier in this module, we introduced the RAS process as a simple equation: identifier + link to Foreign 
Powers =RAS. Now you may be wondering how an identifier is nominated for RAS. NSA must demonstrate and document that e\^^^^^r used to 
query the bulk metadata meets the RAS standard PRIOR to querying the BR and PR/TT bulk metadata repositories. NSA created| | the RAS 

identifier management tool, to streamline the adjudication of the RAS nomination statements and documentation of RAS determinations. 



(TG//G I //Nr ) (HMC Character): Typically, an intelligenceanal^t will gather the necessary information and draft the nomination statement in IRONMAN 
articulating the RAS equation. An HMC, also usinaB I will review the nomination statement and approve or disapprove the request. If the 

nomination statement is for a U.S. person, the( (tool includes functionality that allows the HMCs to forward such requests to OGC for the required 

First Amendment review. In either case, if the RAS nomination is approved, the identifier is now authorized for querying. 



(T5//5 I //N F) (OGC Attorney): Through 
IRONMAN provides the ability to 
of RAS-approved identifiers, and 





NSA documents all RAS-approved identifiers, 
tify, review, approve/disapprove RAS nominations 
exports that list to other systems that require it. 




the rationale used to gain RAS approval. 

is therefore the authoritative source for the list 



(TS//S I //N F) (OGC Attorney): It is important to remember that copies of the documents, such as court orders or reports, are required as part of the 
nomination process. The paper trail should enable an auditor from Department of J ustice (DOJ ) to clearly evaluate all of the evidence presented to support 
a RAS decision. 
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(TG//G I //NO (OGC Attorney): NSA has overseers, specifically the DOJ National Security Division attorneys, who examine the factual support for our R AS 
decision process. They take a look at any notes that the HMCs or someone within the NSA OGC may have included, and they decide whether or not we 
have properly applied the R AS standard to all of the identifiers that are used to query the bulk metadata. So it is critical that we take great carethrouahout 
the process, gathering and presenting the evidence and applying the RAS standard in a consistent manner across all identifier nominations. I 
also provides metrics and other information to facilitate this oversight review and report generation for the DOJ and the F ISC. 

(TS7/G I //NO (OGC Attorney) The Court recognizes that occasionally, NSA may have information suggesting that a target may have used a particular 
identifier only for a limited time. In such cases, an HMC can determine that the RAS standard is met for the specifictimeframe that the identifier was 
believed to be used by the target Such instances are considered Time Bounded and are uniquely dealt with in I I Analysts encountering targets 

under these circumstances should consult with an HMC on how to proceed. ^^^^^^^ 
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(TG//5 I //NT) RAS detemninations for foreign identifiers are legally effective for one 
year. NSA CT has implemented guidance that requires RAS review/re-approval every 
180 days. 

(TS//S I //NF) Although a RAS determination for an identifier reasonably believed to be 
used by a United States person is legally effective for 180 days, NSA CT has 
implemented guidance that requires RAS review/re-approval every 90 days. 



GRAPHIC/AV: 

(U) Use a graphic to show effective dates 
for U.S. and non-U. S. person RAS 
approval 

(U) (Show passing of time and then a 

graphic of an identifier with a "RAS- 

AP PROVE D" or 'DE N I E D" applied over the 

identifier) 



fTS//G I //Nr ) After the sunset of an identifier's RAS approval — or anytime before 
identifier can be submitted for RAS revalidation through the same process. 



the 



(TS//5 l //Nr ) (HMC Character): RAS approvals have sunset or expiration dates which analysts must comply with. Currentiy a RAS approval on a foreign 
identifier, per the FISC, is legally valid for one year. However, NSA CT has taken a conservative approach and implemented guidance that mandates RAS 
review and re-approval every 180 days. Likewise, a RAS approval for an identifier believed to be used by a U.S. person has a legal lifespan of 180 days 
per the FISC, but NSA CT has implemented guidance requiring review and re-approval every 90 days. It is the analyst's responsibility to monitor the sunset 
dates and take appropriate actions before the RAS nomination expires. 

(TS7/S I //Nr ) (HMC Character): Any identifier can be resubmitted for revalidation at any time. Revalidations require proof of the same categories of 
information that was required for the original request. Revalidations should try to validate that the original evidence is still true by presenting any new 
documentation to demonstrate that the identifier is still associated with the Foreign Powers named in the Orders. It is up to the HMCs to make an informed 
revalidation, based on the totality of the evidence. If you are uncertain of your evidence, submit the nomination anyway and work with the HMCs through 
the process. 



TOP SCCRCT//S I //NOrORN 
Page 1A of 17 



TOP SECRET//S I //NOrOR.N 



DATE/PRE PAR ER: 11/09/2010 TAP 



Topic 

(U) Knowledge 
Check 



Home 



Page Classification 

TOP S EC R ET//CO M l NT//NO FO R N 



Exit 



Glossary 



Screen Number 
11 of 13 



Back 



Next 



FRAME ID: 3100 



NEXT FRAME ID: 3110 



BACK FRAME ID: 3090 



ALT TAG: 



GRAPHIC/AV: 



(U) Knowledge Check 

1. ( T5//5 I //NT ) Why is the link between the target and the Foreign Powers an essential part of the RAS 
nomination? 

a) (TS//5 I //NF) It is a key component in reaching the 'probable cause' standard 

b) (T5//5I//NF) It is representative of the terrorist centric scope of the BR and PR/ 1 I authorities 
as noted in the FISC Orders 

c) (U) Because it is required by USSID SP0018 and DoD 5240.1-R 

d) (U) Because it is required in a DIRNSA Memo 

2. (T5//5 I //Nr ) The RAS standard requires that what two facts are articulable? 

a) (TS//SI//NF) The identifier can be tied to a terrorist target and that target can be tied to 

b) (TS//SI//NF) The identifier is not used by a U.S. person and they are engaged in terrorist 
activities 

c) fT5//5i//rtff ) The identifier can be tied to a ta rget and that target is affiliated with| 

d) (TS//SI//NF) The query can be traced back to the analyst who submitted it and the identifier is 
associated with any terrorist group. 



(U) (HMC Character): Let's check what you remember from this topic! 



ANSWERS: 

Question 1: (TS//SI//NF ) Correct! The link between the target and the Foreign Powers is an essential part of the RAS nomination because it is 
representative of the terrorist centric scope of the BR and PR/TT authorities as noted in the FISC Orders. 

(TS//SI//NF) Incorrect. The correct answer is b). The link between the target and the Foreign Powers is an essential part of the RAS nomination because it 
is representative of the terrorist centric scope of the BR and PR/TT authorities as noted in the FISC Orders. 



Question 2: (T5//5 I //Nr) Correct! The RAS standard requires that the following two facts are articulable: 

• The identifier can be tied to a terrorist target, and 

• That target can be tied to | 
(TS//SI//NF) Incorrect The correct answer is a). The RAS standard requires that the following two facts are articulable: 

• The identifier can be tied to a terrorist target, and 

• That target can be tied to ^^^^^^^^B^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^B 
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(No audio or transcript on this page) 



(U) Knowledge Check 

3. (T5//5I//NF) Who may make a RAS determination? 

a) (TG//G I //NT) A Homeland Mission Coordinator (HMC) or an attorney with the Department of 
J ustice 

b) (TG//GI//Nr) An HMC or other official named in the Orders 

c) (T5//5 I //NF) Any reasonable and prudent analyst (and OGC if identifier is believed to be used by 
a U.S. person) 

d) (TS//S I //NF) Only a judge from the F ISC 

4. (TS//5I//NT) Which source of information may be used to justify RAS? 

a) (TG//G I //ND SIGINT reports 

b) ( T5//G I //Nr) Open source information 

c) (TS//S I //Nr) Second Party reports 

d) (T5//5 I //N F) All of the above 

5. (TG//G I //N P ) What additional requirement is needed for an identifier reasonably believed to be used by a 
U.S. person? 

a) ( T5//5 I //Nr ) Must be reviewed by the Attorney General 

b) ( TG//G I //NT) Must be reviewed by the Chief of the Homeland Security Analysis Center 

c) (T5//5I//NF) Must be reviewed by OGC 

d) (TG//G I //Nr ) Two HMCs must agree on the RAS determination 



Question 3: ( T5//5 I //Nr ) Correct! An HMC or other official named in the Orders may make a RAS determination. 

(TG//G I //NT) Incorrect. The correct answer is b). An HMC or other official named in the Orders may make a RAS determination. 

Question 4: (TG//G I //NT ) Correct! SIGINT reports, open source information, and Second Party reports may all be used to justify RAS. 

(TS//SI//NF) Incorrect. The correct answer is d). SIGINT reports, open source information, and Second Party reports may all be used to justify RAS. 

Question 5: (TG//G I //NT ) Correct! If an identifier is reasonably believed to be used by a U.S. person, then it must be reviewed by OGC. 

(TS//S I //NF) Incorrect. The correct answer is c). If an identifier is reasonably believed to be used by a U.S. person, then it must be reviewed by OGC. 
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(U) Now that we have completed this part of your trip you should be able to: 

(TS//S I //NF) Recognize the direct relationship between the Foreign Powers and 
establishing RAS 

(TS//S I //MF) Identify the key components of RAS and how it is applied to candidate 
identifiers 

(T5//5 I //Nr) Identify who can adjudicate and approve a RAS nomination 

(TS//S I //NF) Recognize the requirement associated with identifiers linked to U.S. 
persons - the OGC First Amendment Review 

(T5//S I //Nr) List common sources of information used to construct a RAS 
nomination statement 



(TS//SI//NF) (HMC Character): So remember, RAS nominations are approved by an HMC (or an official named in the Order) BEFORE queries can be 
made using a particular identifier within the BR or PR/TT metadata. 

(U) (OGC Attorney): Now that we have completed this part of the trip you should be able to: 

(T5//5 I //NT) Recognize the direct relationship between the Foreign Powers and establishing RAS 

( TS//G I //N T) Identify the key components of RAS and how it is applied to candidate identifiers 

(TS//SI//NF) Identify who can adjudicate and approve a RAS nomination 

(TS//S I //NF) Recognize the requirement associated with identifiers linked to U.S. persons - the OGC First Amendment Review 
(TS//SI//NF) List common sources of information used to construct a RAS nomination statement 
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COURSE: ( TS//S I //NF ) OVSC1205 Special Training on FISA (Analytical) 
COURSE: ( TS//S I //NF ) OVSC1206 Special Training on FISA (Technical) 

Module 4: (TS//S I //NF ) Access, Sharing, Dissemination, and Retention Under the BR and PR/TT FISC Orders 
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(U) Module 4 

(TS//S I //NF ) Access, Sharing, Dissemination, and Retention Under the BR and PR/TT 
FISC Orders 

(U) This module will enable you to: 

• ( TS//S I //NF ) Distinguish between the analysts authorized to query BR and PR/TT 
metadata and those authorized to view query results 

• ( TS//S I //NF) Recognize the contact chaining restrictions for RAS-approved 
identifiers 

• (TS//S I //NF) Recognize what constitutes unique BR and PR/TT query results 

• (TS//S I //NF) Identify limitations that impact the access, sharing, dissemination, and 
retention of BR and PR/TT query results 

• (TS//S I //NF) Recognize the BR and PR/TT dissemination tracking requirement and 
the additional CT nexus requirement for U.S. person identifiers 



Derived From: NSA/CSSM 1-52 
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( TS//5 I //NF ) (OGC Attorney): During this part of our trip we will identify the limitations regarding access, sharing, disseminating, and retaining of BR and 
PR/TT query results. 

(U) This module will enable you to: 

• ( TS//S I //N F) Distinguish between the analysts authorized to query BR and PR/TT metadata and those authorized to view query results 

• ( T5//5 I //NF ) Recognize the contact chaining restrictions for RAS-approved identifiers 

• ( TS//5 I //NF ) Recognize what constitutes unique BR and PR/TT query results 

• ( TS//S I //IMF ) Identify limitations that impact the access, sharing, dissemination, and retention of BR and PR/TT query results 

• ( T5//5 I //NF ) Recognize the BR and PR/TT dissemination tracking requirement and the additional CT nexus requirement for U.S. person identifiers 

( T5//5 I //NF ) If you are a technical person, you might be asking yourself if this information is directiy applicable to you and your team. Compliance with the 
FISC Orders could be jeopardized by inadvertent or unintended changes in the infrastructure maintained by technical personnel. Therefore, an 
understanding of the requirements outlined in the Orders is important in the event that any technical support functions (data access, presentation, 
underlying system support - both hardware and software, etc.) cause changes to the support infrastructure that would bring NSA's compliance with the BR 
and PR/TT Court Orders into question. 
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( T5//5 I //NF ) (SV Character): Access to BR and PR/TT raw metadata and query results is restricted to those who have the required training and appropriate 
credentials. The Office of the Director of Compliance (ODOC) through the Signals Intelligence Directorate's Office of Oversight and Compliance (SV) 
controls access to the BR and PR/TT FISA metadata, ensuring that only those who have completed all of the required training and have been granted the 
appropriate credentials are permitted to touch the metadata. 



( TS//S I //NF ) Within the analyst workforce, a distinction is made between individuals who are permittedtoauerWhedataandthose who are permitted only 
to view the query results. Individuals who are authorized to query BR and PR/TT metadata sets haveH ^credentials. Division level 

management within a production center determines when query permissions will be granted to analysts based on a mission need, not solely on completion 
of BR and PR/TT FISA Training. Some technical personnel may also require query access, but their queries are for the purposes of data accuracy and 
integrity, not for target or intelligence analysis. Managers of technical personnel who require query permissions will make the determination in concert with 
their organization's compliance office, usually either SV or TV (the Technology Directorate's office of compliance). 



TOP SECRET//S I //NOFORN 
Page3of 39 



TOP SECRET//S I //NOFORN 



TOP SECRET//S I //NOFORN 
Page4of 39 



TOP SECRET//S I //NOFOR I M 



DATE/PREPARER: SLS 



Topic 

( T5//5 I //NF ) BR and PR/TT Data 
Access and Governance 



Home 



Page Classification 

TOR 

5ECRET//COM I NT//NOFORN 



Screen Number 
3 of 27 



Exit 



Glossary 



Back 



Next 



FRAME ID: 4025 



NEXT FRAME ID: 4030 



BACK FRAME ID: 4020 



ALT TAG: 



(TS//SI//NF) How Do I Determine Who Has the Proper Credentials? 
(U) Type I Ho access I land check credentials. 
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( T5//S I //NF ) (SV Character): So, how do you determine if an analyst or technical colleague has the appropriate credentials? | 



lis a tool that can 



you check someone else's credentials against your own. From your NSANet machine, type 



| Lookup Utility. Insert the sid of the analyst or technical 
share in common are displayed. From that you can determine if they hold the 
some reason, you should contact SV4 to verify the individual's credentials before proceeding 




jin your web browser. This takes you to the 
with and hit search, the formal accesses you 
redentials. If the utility is not functioning for 
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(U) Auditing and Access 



( TS//S I //NF ) The Court Orders require that when the metadata is queried for intelligence 
analysis purposes that an auditable record be generated. 

Haudit log includes: 



( TS//S I //NF ) The | 

• Query requests 

• User login 

• IP address 

• Date and time of the access 

(TS//S I //NF) What is the EAR and how does it function as a compliance safeguard? 



( T5//5 I //NF ) (SV Character): The BR and PR/TT Court Orders require that an auditable record be generated whenever metadata is queried for intelligence 



and PR/TT metadata is queried in| |an automatic audit log is generated to enable appropriate oversight of 
queries performed by both analysts and technical personnel and reviews the following on a periodic basis: 



analysis purposes. When th 
these Authorities. SV audits 

• Query requests 

• User login 

• I ntemet P rotocol (IP) address 

• Date and time of the access 

(TV/SI//NFWHMC^:haracter): While these audits are one way to verify that only RAS-approved identifiers are used as seeds to query the BR and PR/TT 
metadata, | | the analytic tool used to query this metadata, employs an Emphatic Access Restriction (EAR) software to provide reasonable 
assurance that only RAS-approved identifiers are queried by analysts. While the EAR is of great benefit for analysts, it should not lessen awareness and 
attention to detail while using the NSA tools and applications associated with BR and PR/TT. We'll discuss the EAR in greater detail later in this module. 



Comment [SLS1] : Notefor audio recording, this 
is pronounced as a wore 



Comment [SLS2] : Notefor audio recording, this 
is pronounced as a word "EAR" (not as letters) 
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(TS//SI//NF) Sourcing of BR and PR/TT Metadata Records 

(TS//SI//NF) Within NSA's source systems of record, BR and PR/TT metadata records 
tagged as to their origin, which allows for: 

• Determining if information is derived from the BR or PR/TT repository 

• Software and other management controls to function properly 


are 




(T5//5I//NF) (OGC Attorney): Another aspect of data access and governance is the requirement for the sourcing of BR and PR/TT metadata records. As we 
mentioned in Module 2, the metadata must carry unique markings, or tags. These tags allow the analyst to determine if a particular piece of information is 
derived from either the BR or PR/TT repository. In addition, these markings enable the EAR software and other management controls to function properly. 
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1. ( T5//5I//NF ) Identify the individuals or groups below who are authorized to receive and view results of 
queries that contain BR and/or P R^rrdate^please check all that apply). 

Individuals wiUil Icredentals ^^^^^^^^^^^^ 

HMCs with | ^ncl analysts with J 

c) Technical personnel witfiH | credentials 

d) Your office chief and oversight personnel by virtue of their positional responsibility 

e) None of the above 

2. ( TS//5 I //NF ) What should you do before sharing the results of a B^or P R/TT query with a co-worker 
working on a target reasonably believed to be associated with the^^V 

a) Read your e-mail to see if your co-worker asked you for the information 

b) Call one of the SOOs in the NSOC to find out if information about your target can be 
released to your co-worker 

c) Verify that the co-worker has the proper credentials to have access to BR and PRATT 
information 

d) All of the above 



(U) (SV Character): Lefs check in and make a few quick notes in our travel journal and see what we remember from this topic. 



ANSWERS: 

Question 1. ( TS//S I /NF ) Correct! a), b), and c) describe individuals and groups holding | B :rec 'entials. 

( TS//S I /NF ) Incorrect Positional authority does not supersede the requirementto have these specific credentials. Not all managers or SV personnel may 
require these credentials for their specific jobs. The correct answers are a), b), and c). 

Question 2. ( TS//S I /NF ) Correct! Before you share any BR or PR/TT query results with a co-worker, you must first verify that he or she has the proper 
credentials to have access to BR and PR/TT information. 

( TS//S I /NF ) Incorrect The answer is c). Before you share any BR or PR/TT query results with a co-worker, you must first verify that he or she has the 
proper credentials to have access to BR and PR/TT information. 
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FRAME ID: 4060 


(TS//SI//NF) Analyst Queries of the BR and PR/TT Metadata 








(U) Have RAS, will query? How? 








NEXT FRAME ID: 4070 


(TS//SI//NF) How do 1 recognize BR and or PR/TT results, and what are "unique" results? 






(U) Once 1 have results, how do 1 handle them? Are there any restrictions? 






BACK FRAME ID: 4050 
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GRAPHIC/AV: 

(U) Display and fade out the questions 
shown as an intra to the topics to be 
covered in this section. 












(U) For the transcript paragraph spoken by 
the Technical Character, consider using a 
creative treatment that shows the character 
for a brief period and then fades her out 
(perhaps a news bulletin or a postcard??). 












(T5//5I//NF) (HMC Character): In this section of the module, we'll cover how analysts query the BR and PR/TT metadata. In addition, we'll go into detail on 
what constitutes BR and PR/TT results and how to tell if they are unique. Since BR and PR/TT unique results may only be shared with individuals who 
have the proper credentials, being able to identify unique BR and PR/TT query results will help you comply with the sharing and handling restrictions. 




(TS//SI//NF) (Technical Character): While this section may appear to be more focused on analytic-specific tools, certain technical personnel also query 
these datasets to provide reasonable assurance of data integrity or to make the metadata usable for intelligence analysis. Therefore, technical personnel 
and their managers should also be aware of guidelines related to queries, handling instructions for query results, in any form, and the requirements related 
to sharing of unique query results, in any form. 
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( TS//SI//NF ) How are Analyst Queries of the BR and PR/TT Metadata Conducted? 



(TS//SI//NF) Queries of BR and PR/TT metadata are conducted tlirough| |the user 
interface to J |As a default, queries are federated with data from other collection 

sources. 
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? [PH FISABR Mode 
IZ] FISABR 
[PI E0 12333 



( T5//5 I //NF ) (HMC 
the user interface to| 



nee RA5 approv ed, an ide ntifier can be used to query the BR and/or P R/TT metadata via authorized versions of 
When launching | | analysts with the appropriate BR or PR/TT credentials have the option to check a box i f the' 

TRY Mode" box when logging into 



wish to in clude BR or PR/TT metadata in their queries. If an analyst checks the 'jFISABR Mode" or 'P 
| will perform a federated query. This means that in addition to either BR or PR/TT metadata, 
additional collection authorities, depending on the analysts credentials. Therefore, when performing^ 
potentially receive results from all of the above collection sources. Users of more recent versions of 
the query, and pick and choose amongst the collection sources that they would like to query. 



iwill also query data collected under 
of the BR or PR/TT metadata, analysts will 
lo have the option, however, to "unfederate" 




omment [SL53]: Notefor audio recording, this 
should be pronounced as trie word FISA trientne 
lettersB R, so simply "FISA B R" 

Comment [a4]: See Screenshot 1. 



TOP SECRET//S I //NOFORN 
Page ID of 39 



TOP SECRET//S I //NOFORN 



TOP SECRET//S I //NOFORN 
Page 11 of 39 



TOP SECRET//S I //NOFORN 



DATE/PREPARER: 



FRAME ID: 4075 



Topic 

( TS//5 I //NF ) Querying the 
BR and PR/TT Metadata 



Page Classification 

TOP 5ECRET//COMINT//NOFORN 



Screen Number 
9 of 27 



Home | Exit | Glossary | Back Next 
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NEXT FRAME ID: 4077 
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( TS//S I //NF ) (HMC Character): Once you are operating within the BR or PR/TT mode of m m remember that you may only use a RAS-approved 
identifier to query the metadata. A RAS-approved identifier that is used to initiate a query of BR or PR/TT metadata is referred to as a 'seed" since it is 
being used to produce a "chain" of metadata contacts, known as contact chaining. 

( TS//5 I //NF ) | ^employs the EAR software to provide reasonable assurance that only RAS-approved identifiers are queried by analysts. Before 
executing a query on an identifier, the EAR verifies that the identifier is RAS-approved. If an analyst attempts to query a non-RAS-approved identifier while 
still in BR or PR/TT query mode, the EAR will provide reasonable assurance that no results are returned for that query: this includes data not derived from 
BR or PR/TT. This query will, how ever, be refle cted in SV's auditing and a justification for the query attempt may be requested. If you are unsure whether 
an identifier is RAS-approved, useB |to determine the identifier's approval status. 
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FRAME ID: 4077 
NEXT FRAME ID: 4080 

BACK FRAME ID: 4075 
ALT TAG: 
GRAPHIC/AV: 

(U) Image of OGC Attorney, HMC 
Character, and SV Character sitting at a 
table 

(U) Look at dm notes and match 
transcript to screen shots. 
(T5//5I//NF) Create animation to explain 
the following: While the BR Order permits 
contact chaining for up to three hops, NSA 
has decided to limit contact chaining to only 
two hops away from the RAS-approved 
identifier without prior approval from your 
Division management to chain the third 
hop. Under PR/TT, the FISC limits the 
number of hops for internet 
communications to only two, and the hop 
counter will not permit these FISC- 
mandated levels to be exceeded 


(TS//SI//NF) Contact Chaining with BR and PR/TT metadata 




(T5//5I//NF) (HMC Character): Once the EAR 


verifies that the seed that the analyst has requested to query is RAS approved, it will allow the analyst to 
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"chain" on that identifier. In the BR and PR/TT Orders, the FISC sets limits on how e xtensive this chaining may be. We refer to this as the number of hops 
from a RAS-approved identifier. For example, let's say your target calls an associate | ^That associate then calls several| |ln 

this example it is one hop from your RAS-ap proved id entifier to the associate and another hop from the associate to a recruit In other words, the associate 
is a "first hop" contact of your target and the I lare 'Second hop" contacts. 



( TS//5 I //NF ) (OGC Attorney): Whil e the BR Order permits contact chaining for up to three hops, NSA has decided to limit contact chaining to only tw o hop: 
away from the RAS-approved identifier without prior approval from your Division management to chain the third hop. Under PR/TT, the FISC limits the 
number of hops for internet communications to only two. Technical controls will not permit these F ISC-mandated hop levels to be exceeded. 



Comment [a5] : We can probably use some of the 
existingscreenshote we trade to also i 1 1 ustrate the 
hops. 



( TS//S I //NF ) (HMC Character): If another RAS-approved identifier is encountered within the authorized number of hops from the previous RAS-approved 
identifier, the number of hops resets to allow a contact chain to be generated out the authorized number of hops from the newly encountered RAS- 
approved identifier. 



TOP SECRET//S I //NOFORN 
PageMof 39 



TOP SECP.ET//S I //NOFORN 



DATE/PREPARER: 



FRAME ID: 4080 



NEXT FRAME ID: 4090 



BACK FRAME ID: 4077 



ALT TAG: 



GRAPHIC/ AV: 

(U) Look at J J notes and match 
transcript to screen shots. 



Topic 

( T5//5 I //NF ) Querying the 
BR and PR/TT Metadata 



Home 



Page Classification 

TOP SECRET//COM I NT//NOFORN 



Screen Number 
11 of 27 



Exit 



Glossary 



Back 



Next 



(TS//SI//NF ) What is a Query Result and how do I know if it is a BR or PR/TT Query 
Result? 

( TS//S I //NF ) Quer y Result: Queries produce results in the form of a contact chain 
presented in^^^bmnat; each chain is comprised of individual contacts derived from data 
returned from the multiple collection sources queried. Each contactyline within a chain 
represents an individual result 



( Comment [a6]: This is illustrated by screenshot 2 1 



( TS//S I //NF ) (HMC Character): When you query a RAS-approved identifier in I |n BR or PRATT modes, | g»ill return a ^^|file, usually 
referred to as a chain, which is made up of the individual first hop contacts of the seed. Bearing in mind the hop restrictions just discussed, analysts may do 
further chaining on those contacts. Each of these contacts, or line within the chain, represents an individual resul t Remember, unless you choose to 
unfederate your query as we described earlier, these results may have been obtained under a variety of collection authorities. 

( TS//5 I //NF ) It is possible to determine the collection source or sources of each result within the chain by examining the Producer Designator Digraph 
(PDDG)/SIGINT Activity Designator (SIGAD) and collection source(s) at the end o f the line. 



Comment [a7]: This is illustrated by screenshot 2 



( T5//5 I //NF ) If at least one source of a result is BR or PR/TT metadata, the classification at the beginning of the line will contain the ph rases FISABR or 
PR/TT, respectively. In addition, in the source information at the end of the line, the SIGAD ^^^B^^B^^^^^^^^^^^^^^^^^MSR d ata can be 
by SIGADs withB 

collected after October found H HFor a 

comprehensive listing of all the BR and PR/TT SIGADs as well as information on PR/TT data collected prior to November of 2009, contact your 



Comment [SLS8]: Notefor audio recording, this 
should be pronounced as a word "SIGAD" ( not 
spelled out in letters as S I G A D) 



Comment [a9]: I really think we need some 
For PR/TT, dato( pictures to illustrate 
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organization's management or subject matter expert 



(T5//3 1//N l~ ) Since it is possible that one communication event will be collected under multiple collection authorities (and multiple collection sources), not al 
of the results will be unique to one collection authority (or collection source). Keep in mind that the classification at the beginning of each result only 
indicates the highest level classification of that result, and does not necessarily reflect whetinei^yTesultwa^unicju^oonecollectior 
source). If a result was obt ained under multiple authorities (or sources), you will see morej 

I Here are examples of results originating from multiple collection sources. None of these results are considered BR- or PR /TT- 



|Comment [SLS10]: Notefor audio recording, 
the acronym PDDG should be spelled out in letters 
"P D D G" foil owed by the word "SI GAD" - so this 
phrase wi 1 1 be recorded as "Producer Desi gnator 
Digraph, or PDDG or SI GAD" 



Comment [all]; Screenshot 
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(TS//SI//NF ) What is a BR- or PR/TT-Unique Query Result? 

(U) (Insert image of OGC Attorney and HMC Character sitting at a table discussing the 
talking points below shown on a white board) 

( TS//S I //NF ) BR- or PR/TT-"unique" query results are those contacts within a chain 
solely derived from the BR or P R/TT metadata and not duplicated in the results originating 
from any other authorities. 



(T5//5 I //NF) (HMC Character): In the examples we just discussed, none of the results were unique to any one collection authority. Frequently, however, 
you'll find that some of the results within the chain are unique to one particular collection authority. A BR- or PR/TT-unique query result is any piece of 
information that NSA would not have had but for the BR or PR/TT metadata from which it was drawn. In other words, BR or PR/TT was the ONLY source of 
that individual contact/query result 



(TS//5 I //NF) Here are some examples: example A is "E.O. 12333-unique," while B is 'PR/TT-unique," and C is "BR-unique.' 



Comment [al2]: Againshow previous examples, j 



(TS//5 I //NF) Sharing restrictions in the FISC Orders only apply to unique BR or PR/TT query results. If query results are derived from multiple sources anc 
are not unique to BR and PR/TT alone, the rules governing the other collection authority would apply. We will discuss these sharing and handling 
restrictions in greater depth shortly. 



Comment [SLS13]: Note for audio recording: 
we will want sometime in between saying example 
A is "E.O. 12333-unique," and while B is 
"PR/TT-unique," and and C is "BR-unique." 

to allow learner to look at the examples. Please 
allow some "quiet' space that can be duplicated 
to the amountof time needed. THANKS! © 
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FRAME ID: 4100 


(TS//SI//NF) BR or PR/TT Query Results - Not J ust a Line Within a Chain 
(TS//SI//NF) Examples of BR and/or PR/TT Query Results include: 






NEXT FRAME ID: 4105 


• A specific identifier 

• 'Identifier A was in contact with Identifier B" 










• A .cml file (i.e. the entire contact chain/result set) that contains BR or PR/TT query 




BACK FRAME ID: 4090 


results 

• A written or electronic depiction of a chain (i.e., the .cml file itself) orthe analysis or 
partial analysis of a chain that includes BR or PR/TT results 

• A compilation or summary of first- and second-level contacts from a RAS-approved 




ALT TAG: 




GRAPHIC/AV: 






seed 












• A draft or a finished but not yet disseminated report 








• Any other BR or P R/TT information returned following a RAS-approved federated 






query 











TOP SECRET//S I //NOFORN 
Page 18 of 39 



TOP SECRET//S I //NOFORN 



( TS//5 I //NF ) (OGC Attorney): Before we discuss sharing and handling restrictions of BR- and PR/TT-unique query results, it is impor tantto understand that 
a BR or PR/TT query result is not just a line within the chain that is presented to you after you run a BR or PR/TT query in| |Any information that 
you derive, extract, or manipulate from that particular line in the chain becomes a BR or PR/TT result Given that a source of the result is derived from BR 
or PR/TT metadata, any adaptation of that result, including information provided orally or in writing, even a tip or a lead, remains a BR or PR/TT query 
result 



( T5//5 I //NF ) (OGC Attorney): In addition, other examples of items that have been deemed to be BR and PR/TT query results include: 
A specific identifier 

'Identifier A was in contact with Identifier B" 

A ^^file (for example the entire contact chain/res ult se t) that contains BR or PR/TT query results 

A written or electronic depiction of a chain (like the ^^|file itself) or the analysis or partial analysis of a chain that includes BR or PR/TT results 
A compilation or summary of first- and second-level contacts of a RAS-approved seed 
A draft or a finished but not yet disseminated report 

Any other BR or PR/TT information returned following a RAS-approved federated query 



Comment [SLS14] : Note for audio recording, 
theSMEs would likeforttiis to be pronounced "the 
^|rile" I know this might sound a little odd 
sincewedon'tsaythingslike"thedotpdf file" but 
just trust me on this one because we had a 5 minute 
argument about it i n a SM E meed ng. UGH ! 

in 
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FRAME ID: 4105 


(TS//SI//NF) BR or PR/TT Query Results - Not J ust a Line Within a Chain 
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(T5//5I//NF) (HMC Character): So, for example, if you run a BR or PR/TT query on a particular RAS-approved e-mail identifier and it returns information 
that depicts identifier A, the RAS-approved seed, was in direct contact with identifier B and the source of the metadata is BR or PR/TT, then just the fact 
that identifier A is communicating with identifier B is considered a BR or PR/TT query result 

(TS//SI//NF) (HMC Character): In addition, any summary of that information would also be a BR or PR/TT query result So, if you knew that identifier A 
belonged to J oe and identifier B belonged to Sam, and the fact of that contact was derived from BR or P R/TT metadata, if you communicate orally or in 
writing thatj oe talked to Sam, even if you don't include the actual e-mail account or telephone numbers that were used to communicate, this is still a BR or 
PR/TT query result 

(TS//SI//NF) (OGC Attorney): Remember, if these results are determined to be BR- or PR/TT-UNIQUE, they are subject to sharinq and handlinq 
restrictions. 
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( TS//SI//NF ) Sharing and Handling Restrictions of BR- or PR/TT-Unique Query 
Results 

( TS//S I //NF ) Examples of handling restrictions for BR and PR/TT unique query 
results: 

• Any document, .cml, or other file containing BR- or PR/TT-unique information may 
only be stored on the analysts personal folders, or an access-controlled, shared 
location 

• Query results canr^^^^^^^^^^y system where the results would be shared with 

individuals without^ 

• BR- or PR/TT-unique results may not be queriecHritoolsvvhere user queries are 
visible to other analysts (who may not have| | or can be 

manipulated by behind the scenes analytics 



Comment [al5]: There is no such list of tools 
that are ok/ not ok to query, btw. 



(TS//SI//NF) These restrictions apply to information that is SOLELY unique to BR and 
PR/TT and do NOT apply to information which is NOT unique to BR or PR/TT! 



( TS//5 I //NF ) (OGC Attorney): Remember, BR- or PR/TT-unique query results are those contacts within a chain solely derived from the BR or PR/TT 
metadata and not duplicated in the results originating from any other authorities. Any oral or written depiction, manipulation, or summary containing that 
information is also a unique query result Until they are officially disseminated, BR- or PR/TT-unique results may only be shared with individuals who hold 
the proper credentials to receive or view BR or PR/TT information. The requirement is imposed because of the special handling restrictions that we will 
discuss later in this Module. Without the proper training, the F ISC-imposed handling restrictions may not be followed. 

( TS//S I //NF ) (HMC Character) Unless these unique results have been disseminated, such BR- or PR/TT-uniqueinforrnation may only be shared with 
individuals who have the proper credentials to receive or view BR or PR/TT information. Remember, use | |'- r> determine a user's credentials. Th' s 

means: 

« Any doc ument, ^M. or o ther file containing BR- or PRTT-unique information may only be stored on the analyst's personal folders, or an access- f Comment [SLS17]: pieasesay 



Comment [SLS161^Notefor audio recording, 
this is pronounced 
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or 



can be manipulated by behind the scenes analytics. If you have questions regarding which tools are acceptable to further research query results, 
please contact your management or technical director. 

( TS//S I //NF ) (SV Character) However, as we've discussed, not all BR or PR/TT results are unique. If a query result indicates it was derived from another 
collection source in addition to BR or PR/TT, the rules governing the other collection authority would apply to the handling and sharing of that query result 
For example, this result came from both BR and E.O. 12333 collection; therefore, because it is not unique to BR information, it would be ok to inform non- 
BR cleared individuals of the fact of this communication, as well as task, query, and report this information according to standard E.O. 12333 guidelines. 

( TS//5 I //NF ) (SV Character) In summary, if a query result has multiple collection authorities, analysts should source and/or report the non-BR or PR/TT 
version of that query result according to the rules governing the other authority. But if it is unique to either the BR or PR/TT authority then it is a unique 
query result with all of the applicable BR and PR/TT restrictions placed on it In both cases, however, analysts should not share the actual chain containing 
BR or PR/TT results with analysts who do not have the credentials to receive or view B R or PR/T T information. In such an instance, if it is necessary to 
share the chain, analysts should re-run the query in the non-BR or non-PR/TT areas of| | and share that .cml. 
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(U) Retention of Metadata and Query Results 

(TS//SI//NF) NSA must destroy BR and PR/TT metadata no later than five years (60 
months) after initial collection 

(TS//SI//NF) The FISC has not imposed any destruction requirement on BR or PR/TT 
query results 




(TS//5I//NF) (OGC Attorney): The Court Orders mandate destruction of the metadata five years or 60 months after initial collection. NSA destroys the BR 
and P R/TT metadata no later than five years after collection. There are no exceptions to this requirement when it comes to the bulk metadata. 

(TS//SI//NF) (HMC Character): The destruction requirement applies to the bulk metadata; it does not apply to query results that have been generated as a 
result of queries of RAS-approved identifiers. Once we have queried the metadata we have selected metadata, or query results, and the 60-month cutoff 
does not apply. 
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(U) Knowledge Check 2 

3. ( T5//S I //NF ) Please complete the following sentence. The Emphatic Access Restriction (EAR) 



a) createsar^utomarjc auditable record to allo w for oversight of these authorities. 

b) alerts | (when an individual without H (attempts to conduct a 
query. 

c) forwards the query request to the HMC for approval. ^^^^^^^^ 

d) prohibits non-RAS-approved identifiers from being queried in ( 

e) None of the above. 

4. ( TS//5 I //NF ) Assuming that the following answers describ^uniqueBF^orPR^T query results, which of the 
following could be shared with co-workers who do not havej 

a) Having a fellow analyst review the draft of a report that contains P R/TT-deri ved information 

b) A summary of direct or in direct contacts of a RAS- approved identifier 

your manager that( (contacted | ( as 

noted in the PR/TT query you recently performed 

d) E -mailing an electronic depiction of a BR or PR/TT contact chain or a pattern 

e) None of the above. 



5. (T5//5 I //NF) TRUE or FALSE: If a query result indicates that the source of information is both Executive 
Order 12333 collection and PR/TT collection, then the analyst must handle the E.O. 12333 result according 
to the PR/TT rules. 

a) True 

b) False 



(U) (HMC Character): Let's make a few notes in ourtravel journal and check to see what you remember from this topic! 
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ANSWERS: 

Question 3. ( TS//S I //NF ) Correct! The EAR prohibits non-RAS-approved identifiers from being queried in 
( TS//S I //NF ) Incorrect The correct answer is d). The EAR prohibits non-RAS-approved identifiers from being queried in 



Question 4. ( TS//S I //NF ) Correct! None of the examples listed should be shared with anyone outside of 
( TS//S I //NF ) Incorrect. The correct answer is e). None of the examples listed should be shared with anyone outside of 




channels. 



Question 5. ( TS//S I //NF ) Correct! If a PR/TT query result can also be sourced to Executive Order 12333, then the information is considered E.O. 12333 
collection and follows the E.O. 12333 processes and procedures. 

( TS//S I //NF ) Incorrect. If a PR/TT query result can also be sourced to Executive Order 12333, then the information is considered E.O. 12333 collection and 
follows the E.O. 12333 processes and procedures. 
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(U) Knowledge Check 2 

6 . (TG//5 I //ND I f! 




is your RAS-approved identifie r, and he e-mails 
who then e-mails | Hwho then e-mails 

how many hops is I H from your RAS-approved 




identifier? Are you allowed to chain that far in the PR/TT mode of 



a) 4 hops, no, unless one of the contacts between^ Jancl I l' s RAS 

approved. 

b) 3 hops, no (unless one of the contacts between j 
RAS approved). 

c) 4 hops, yes. 

d) 3 hops, no. 

e) 2 hops, yes. 



7. ( T5//5 I //NF ) If Badguyl's identifier is RAS-approved, and he calls Associatel, who then calls 
Unknownguy, who then calls Unknownguy2, how many hops jsJnknownguy2 from your RAS-approved 
identifier? Are you allowed to chain that far in the BR mode ol| 

a) 4 hops, no, unless one of the contacts between badguyl and unknownguy2 is RAS 
approved. 

b) 3 hops, yes (with management approval). 

c) 4 hops, yes. 

d) 3 hops, no. 

e) 2 hops, yes (with management approval). 
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ANSWERS: 

Question 6. ( TS//S I //NF ) Correct! The 
far unless one of the contacts between 
( TS//S I //NF ) Incorrect The correct answer is b). The 
permitted to chain this far unless one of the contacts' 

Question 7. ( TS//S I //NF ) Correct! The 
approval. ^ j 
( TS//S I //NF ) Incorrect. The correct answer is b). The 
management approval. ' 




is 3 hops from the RAS-appr oved identifier. You would not be permitted to chain this 
|is RAS approved. 

hop l S_fi22l52^£A^^2PI2 v ^^^ ent '^ er ■ ^ ou wou ' c ' not De 
His RAS approved. 

is 3 hops from the RAS-approved identifier. You are permitted to chain this far with management 
s 3 hops from the RAS-approved identifier. You are permitted to chain this far with 
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(TS//SI//NF) Dissemination of BR- and PR/TT- Derived Information 

(TS//SI//NF) Dissemination of BR and PR/TT results is distributing information to external 
customers in any form to include oral or written form 

(TS//SI//NF) Topics covered: 

• Information of foreign intelligence value which contains only foreign person information 
that IS NOT unique to BR or PR/TT 

• Information on U.S. persons (minimized) or foreign target activity unique to BR or PR/TT 
metadata 

• Information on U.S. persons (unminimized) unique to BR or PR/TT 


(TS//SI//NF) (OGC Attorney): Now lefs focus our attention on the dissemination of BR and PR/TT results. We define dissemination of BR and PR/TT 
results as distributing information to external customers in any form to include oral or written form. Lefs say you perform a BR or PR/TT query using a 
RAS-approved identifier, and the query returns good foreign intelligence information based on unique BR or PR/TT metadata that you would like to report 
to Intelligence Community customers. What should you do? In this topic we will discuss to what extent we can use standard processes and procedures for 
the dissemination of this information and to what extent we must use special processes and procedures for the dissemination of this special foreign 
intelligence information. Given the sensitive nature of this Program, you will not be surprised to hear that there are special rules that apply to the 
dissemination of this information. 
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(TS//SI//NF) Information Derived Exclusively from BR or PR/TT - Additional Requirements 



(TS//S I //NF) Standard reporting practices and policies (including sourcing requirements and 
procedures and USSID SP0018 minimization) apply to BR and PR/TT query results 

(TS//S I //NF) Two additional, BR- and PR/TT-specific requirements: 



The Counterterrorism (CT) nexus requirement applies to BR- and P R/TT-derived 
unminimized U.S. person information, but does notapplyto BR- or P R/TT-derived non- 
U.S. person information or BR- or P R/TT-derived minimized U.S. person information 
The dissemination tracking requirement applies to all BR- and P R/TT-derived 
information 



(TS//S I //NF) (OGC Attorney): First of all, every disseminated report from NSA must include sourcing information so that we know where the information 

came from, as well as follow all USSID SP0018 minimization requirements and procedures. For BR- and P R/TT-derived information, the analyst or r eport^ Comment [SLS18]: update 7/13/11 from the 
needs to make sure that the information included in that report is properly sourced to the appropriate BR or PR/TT authority. 



SM Es: PI ease record at U SSI D 18 (do not say SPEW 
or SPOW, just "USSID 18" 



(TS//S I //NF) In addition, the Court Orders for both the BR and PR/TT authorities have imposed two unique, stringent requirements with respect to 
disseminating information from these authorities. The first is the Counterterrorism, or CT, nexus requirement and the second is the dissemination tracking 
requirement 
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(TS//S I //NF) The CT Nexus Requirement 



( TS//S I //NF) Prior to the dissemination of BR- or P R/TT-derived unminimized U.S. person 
information outside of NSA, one of the designated approval authorities must determine: 

(a) that the U.S. person information is related to CT information, and 

(b) thatthe U.S. person information is necessary to understand the CT information 
or to assess its importance 



(TS//5 I //NF) (OGC Attorney): The CT nexus requirement applies only to U.S. person information. If you run a query and the information returned is all 
foreign person information, then the CT nexus requirement does not apply to this situation. However, if your query results include U.S. person information 
derived from BR or PR/TT and you want to disseminate that information to an external customer, such as the FBI, then this requirement must be met prior 
to dissemination, in any form. Traditionally, under USSID SPOOlgj , if there is a piece of unminimized U.S. person information that you would like to 
disseminate, one of the designated approval authorities (to be covered on the next screen) needs to determine that the information is necessary to 
understand the foreign intelligence in that particular intelligence report before the information can be released. For BR and PR/TT, the requirement is 
slightiy different 

(TS//S I //NF) (OGC Attorney): With respect to the BR and PR/TT authorities, the unminimized U.S. person information not only has to relate to and be 
necessary to understand the foreign intelligence information in the report, but it has to relate to and be necessary to understand the Counterterrorism 
information. 



Comment [SLS19]: update 7/13/11 from the 
SM Es: Please record at U SSI D 18 (do not say SPEW 
or SPOW, just "USSID 18" 
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(TS//5 I //NF) (HMC Character): Recall the RAS process and how you derived this information. The identifier you used to generate this information was 
^^jovj^^^^^oj^^^^^^j^gjj^^^^DUjd^o^^^^^ai|^r^reasonably believed to be used by someone | 

(T5//5 I //NF) (HMC Character): It might seem as though the information would most certainly be counterterrorism-related since, due to the RAS approval 
process, you wouldn't have this U.S. person information from a query of BR or PR/TT if it weren't related to counterterrorism. In the majority of cases, it will 
be counterterrorism-related; however, the nature of the counterterrorism target is that it often overlaps with several other areas that include 
countemarcotics, counterintelligence, money laundering, document forging, people and weapons trafficking, and other topics that are not CT-centric. Thus, 
due to the fact that these authorities provide NSA access to a high volume of U.S. person information for counterterrorism purposes, the Court Order 
requires an explicit finding that the information is in fact related to counterterrorism prior to dissemination. Therefore, one of the approved decision makers 
must document the finding using the proper terminology. It must state that the information is related to counterterrorism and that it is necessary to 
understand the counterterrorism information. 



(TS//S I //NF) (OGC Attorney): While the USSID SP0018 process is the most familiar method of governing the dissemination of unminimized U.S. person 
information obtained from traditional SIGINT means, the CT nexus requirement is an additional protection for U.S. person information being disseminated 
when the BR or PR/TT authorities, and metadata obtained by virtue of those authorities, is the source of the information. The FISC wants to ensure that the 
authorities are being used for counterterrorism purposes as intended, so consider the CT nexus requirement a step above justifying a foreign intelligence 
requirement 



T OP 5ECr\CT//G I //NOron.N 
Page 31 of 39 



TOP SECRET//S I //NOFOR I M 



DATE/PREPARER: 11/23/2010 SLS 



FRAME ID: 4170 



NEXT FRAME ID: 4180 



BACK FRAME ID: 4160 



ALT TAG: 



GRAPHIC/AV: 

(U) Image of OGC Attorney, HMC 
Character, and SV Character sitting at a 
table 



Screen 

(U) Dissemination 
Requirements 



Home 



Page Classification 

TOP SECRET//COMINT//NOFORN 



Screen Number 
22 of 27 



Exit 



Glossary 



Back 



Next 



( TS//SI//NF ) Dissemination Approval Authorities 

( TS//S I //NF ) Only those in the following NS A positions have the authority to approve the 
dissemination of BR- or P R/TT-derived U.S. person(s) information: 

(U) USSID SP0018 

• (U //FOUO ) The Chief and Deputy Chief of Information Sharing Services 

• (U //FOUO ) The Senior Operations Officers (SOOs) of the National Security 
Operations Center (NSOC) 

• (U //FOUO ) The Director and Deputy Director of the Signals Intelligence Directorate 

• (U //FOUO ) The Director and Deputy Director of NSA 

(U) This approval authority cannot be delegated to anyone else! 



(T 5//5 I //NF ) (OGC Attorney): Certain positions are authorized to validate the CT nexus requirement, as we just discussed, and approve the dissemination 
of U.S. person(s) information that we obtain from these two authorities. 

( TS//5 I //NF ) (OGC Attorney): Recall from your USSID SP0018 training, there are certain positions at NSA which have the authority to approve the 
dissemination of information that would identify a U.S. person either by name or by context. Those positions are listed in USSID SP0018 and include the 
Chief and Deputy Chief of the Information Sharing Services Office, the Senior Operations Officers (SOO) within the National Security Operations Center 
(NSOC), the Director and Deputy Director of the Signals Intelligence Directorate (SID), and in some cases they include the Director and Deputy Director o 
NSA. 

( TS//S I //NF ) (HMC Character): The list of positions which can approve the dissemination of unminimized U.S. person information derived from unique BR 
and PR/TT query results is the same as those named in USSID SP0018. 



Comment [SLS20]: Note for audio recording, 
this is pronounced as a word "SOO" (rhymes with 
"new", but does not rhyme with "sew a dress") 



Comment [SLS21]: Note for audio recording, 
this is pronounced "N sock" 
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( TS//5 I //NF ) (OGC Attorney): It is important to note that the authority to approve the dissemination of U.S. person information cannot be delegated. This 
responsibility is assigned only to the positions named in the BR and PR/TT Court Orders. Lefs say, for example, thatthe Chief and Deputy Chief of 
Information Sharing Services Office, the two individuals who on a normal daily basis would be making the decision, are both on vacation on the same day. 
In this instance, someone else within their office may be the acting chief on that day; however, the acting chief cannot make the decision to disseminate 
U.S. person information. 

( TS//S I //NF ) (HMC Character): Under these circumstances, if information about a U.S. person must be disseminated on that day, then you should send 
your dissemination request to one of the other positions named in the Orders. This would logically be the NSOC SOO. 

( TS//S I //NF ) (OGC Attorney): With respect to non-U. S. person information, standard NSA practices and policies (such as proper sourcing information) 

apply- 
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(U) Dissemination Tracking 

(TS//SI//NF) NSA must report to the FISC every 30 days the number of instances since the 
preceding report in which NSA disseminated BR- or P R/TT-derived information, in any 
form (oral, written, formal, or informal), with anyone outside of NSA 

(U) For more information, please contact | 


(TS//5I//NF) (OGC Attorney): The other requirement which applies to both U.S. person information as well as foreign person information, is trie 
dissemination tracking requirement regarding the dissemination of BR- and P R/TT-derived information. The Orders require NSA to track and report to trie 
FISC every instance in which NSA disseminates any information derived from either of these two authorities. 

(TS//SI//NF) (HMC Character): This refers to information disseminated in a formal report as well as information disseminated informally such as written or 
oral collaboration with the FBI. We need to count every instance in which we take a piece of information derived from either of these two authorities and 
disseminate it outside of NSA. 

(TS//SI//NF) (HMC Character): Normally an NSA product report is the record of a formal dissemination. In the context of the BR and PR/TT Programs, an 
official RFI response or Analyst Collaboration Record will also be viewed as dissemination. Because this FISC requirement goes beyond the more standard 
NSA procedures, additional diligence must be given to this requirement NSA is required to report disseminations formal or informal to the FISC every 30 
days. 
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( TS//S I //NF ) Once approved for dissemination, BR- or P R/TT-derived information can be 
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(U) Possible cutaway images may include: 
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is approved for dissemination 

( TS//5 I //NF ) (OGC Attorney): Once BR and PR/TT information has been disseminated (such as in a product report, RFI, or briefing), generally speaking, 
there are no follow-on restrictions that either NSA or our customers need to follow regarding the sharing or dissemination of tfiat information contained in 
tfie report The Orders do not impose any restrictions on the use of formally reported information from the BR or PR/TT authorities: therefore, this 
information can be used for any lawful purpose. 



( T5//5 I //NF ) If BR- or P R/TT-derived information is disseminated outside of NSA, then the restrictions on internal sharing of that same information at NSA 



no longer apply. For ex 
other tools such as thel 



jsseminated can be shared outside of 



■channels, and the identifiers can be used in 
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(U) Knowledge Check 3 

8. (TS//SI//NF) Identify the additional requirements reqardinq the dissemination of unminimized U.S. person 
information derived from BR or PR/TT information: 

a. The Counterterrorism nexus check 

b. The Counterintelligence nexus check 

c. The dissemination tracking requirement 

d. The sourcing requirement 

e. Both a) and c) 

9. (TS//SI//NF) TRUE or FALSE: the dissemination tracking requirement applies to only U.S. person BR- or 
PR/TT-derived information. 

a. TRUE 

b. FALSE 


NEXT FRAME ID: 4210 
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GRAPHIC/AV: 


(U) (OGC Attorney): Before we move on to th 


e next part of our trip, lefs make a few notes in our travel journal. 


ANSWERS: 

Question 8. (TS//SI//NF) Correct! The Court Orders for both the BR and PR/TT authorities have imposed two unique requirements with respect to 
disseminating information from these authorities. The first is the Counterterrorism, or CT, nexus check (which applies only to U.S. person information), and 
the second is the dissemination tracking requirement 

(TS//SI//NF) Incorrect, the correct answer is e). The Court Orders for both the BR and PR/TT authorities have imposed two unique requirements with 
respect to disseminating information from these authorities. The first is the Counterterrorism, or CT, nexus check (which applies only to U.S. person 
information), and the second is the dissemination tracking requirement. 

Question 9. (TS//SI//NF) Correct! The dissemination tracking requirement applies to both U.S. person and non-U. S. person BR- and PR/TT-derived 
information. 

(TS//SI//NF) Incorrect The dissemination tracking requirement applies to both U.S. person and non-U. S. person BR- and PR/TT-derived information. 
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10. ( T5//SI//NF ) Forthe purpose of the BR and PR/TT Programs 

information to customers in any form. is the provision of BR and PR/TT FISA query results with 

others inside of NSA authorized to receive BR and PR/TT query results. 

a) Dissemination, Distribution 

b) Sharing, Dissemination 

c) Dissemination, Sharing 

d) Sharing, Distributing 

11. ( TS//SI//NF ) Which one of the following NSA positions does not have the authority to approve the 
dissemination of BR- or P R/TT-derived unminimized U.S. person information? 

a) The SOOs in the NSOC 

b) The Director and Deputy Director of the Signals Intelligence Directorate 

c) The Director and Deputy Director of NSA 

d) The Office of General Counsel (OGC) 

e) The Chief and Deputy Chief of Information Sharing Services 



ANSWERS: 

Question 10. ( TS//S I //NF ) Correct! Dissemination is the more formal distribution of information to customers in either oral or written form. Sharing is the 
provision of BR and PR/TT FISA query results with others inside of NSA authorized to receive BR and PR/TT query results. 

( TS//S I //NF ) Incorrect The correct answer is c) Dissemination is the more formal distribution of information to external customers in either oral or written 
form. Sharing is the provision of BR and PR/TT FISA query results with others inside of NSA authorized to receive BR and PR/TT query results. 

Question 11. (TS//S I //NF) Correct! The answer is d) The OGC does not have the authority to approve the dissemination of BR- or P R/TT-derived unminized 
U.S. person information. 

(TS//S I //NF) Incorrect The answer is d) The OGC does not have the authority to approve the dissemination of BR- or PR/TT-derived unminized U.S. 
person information. 
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(U) Now that we have completed this part of your trip you should be able to: 

• ( TS//S I //NF ) Distinguish between the analysts authorized to query BR and PR/TT 
metadata and those authorized to view query results 

• ( TS//S I //NF ) Recognize the contact chaining restrictions for RAS-approved 
identifiers 

• ( TS//S I //NF ) Recognize what constitutes unique BR and PR/TT query results 

• ( TS//S I //NF ) Identify limitations that impact access, sharing, dissemination and 
retention of BR and PR/TT query results 

• ( TS//S I //NF ) Recognize the BR and PR/TT dissemination tracking requirement and 
the additional CT nexus requirement for U.S. person identifiers 



( TS//5 I //NF ) (OGC Attorney): Remember, you are responsible for ensuring that the recipient of query results is authorized to receive these results. Also, 
you must be mindful of the special restrictions for dissemination, either oral or written, of the BR- and P R/TT-derived information. 

(U) (OGC Attorney): Now that we have completed this part of the trip you should be able to: 

• ( TS//5 I //NF ) Distinguish between the analysts authorized to query BR and PR/TT metadata and those authorized to view query results 

• ( T5//5 I //NF ) Recognize the contact chaining restrictions for RAS-approved identifiers 

• ( TS//S I //NF ) Recognize what constitutes unique BR and PR/TT query results 

• ( TS//S I //NF ) Identify limitations that impact access, sharing, dissemination, and retention of BR and PR/TT query results 

• ( TS//S I //NF ) Recognize the BR and PR/TT dissemination tracking requirement and the additional CT nexus requirement for U.S. person identifiers 
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(U) The Analytical and Technical Work Roles 
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(U) This module will enable you to: 

• (U) Compare and contrast the analytical and technical work roles 

• (U) Identify analytical and technical personnel's authorization to touch the data 
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• (U) Identify how the authorities impact interactions with other roles and the data 
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(U) (Technical Character): During this part of our trip we will compare and contrast the analytical and technical work roles and provide you with a basic 
knowledge of the two distinct areas. This will serve as an introduction to the more role-specific module you will complete later. 


(U) This module will enable you to: 

• (U) Compare and contrast the analytical and technical work roles 

• (U) Identify analytical and technical personnel's authorization to touch the data 

• (U) Identify how the authorities impact interactions with other roles and the data 









TOP SCCRET//S I //NOrORN 
Page 1 of 30 



Derived From NSA/CSSM 1-52 
Dated: 20070108 
Declassify On: 20350501 



TOP SLXRL"r//5 l //NOrORN 



DATE/PREPARER: SLS 


Topic 

(U) The Analytical Work 
Role 


Page Classification 

TOP S E C R ET//S I//NO FO R N 


Screen Number 
2 of 8 


Home 


Exit 


Glossary 


Back 


Next 


FRAME ID: 5020 

NEXT FRAME ID: 5030 

BACK FRAME ID: 5010 
ALT TAG: 
GRAPHIC/AV: 

(U) Begin with image of HMC Character 
and Technical Character sitting at a table, 
then provide a close up of the HMC 
Character 


(U) The Analytical Work Role 

(TS//SI//NF) The Analytical Work Role includes these primary functions: 

• HMC 

• Those who conduct intelligence analysis queries 

• Those who can view and disseminate the results of intelligence analysis queries 


(TS//SI//NF) (HMC Character): The analytical work role includes three primary functions: Homeland Mission Coordinators (HMC), those who can conduct 
intelligence analysis queries, and those who can view and disseminate the results of intelligence analysis queries. 

(T5//5I//NF) Homeland Mission Coordinators, or HMCs, review and approve the RAS nominations. The analysts and HMCs work through the RAS approval 
process together to get the identifiers RAS-approved. 

(T5//5I//NF) Recall from the last module that not al^nalvstsarepemTitted to conduct contact chaining queries. Those who are permitted to conduct 
queries of the bulk metadata have been granted U ^credentials. Those who are permitted to view and disseminate query results, but 
not conduct queries, have been granted | (credentials. 



TOP SCCRET//S I //NOrORN 
Page 2 of 3D 



TOP SECRET//S I //NOroriN 



DATE/PREPARER: SLS 



Topic 

(U) The Technical Work 
Role 



Home 



Page Classification 

TOP SECRET//S I //NOFORN 



Exit 



Glossary 



Screen Number 
3 of 8 



Back 



Next 



FRAME ID: 5030 



NEXT FRAME ID: 5040 



(U) The Technical Work Role 

( TS//S I //NF ) The Technical Work Role is made up of tw o main functions: 

• Support to Collection and Metadata | 

• Support to Storage, Presentation, and Maintenance 
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( TS//S I //NF ) (Technical Character): The work performed by technical personnel in support of the Bulk Metadata Programs assists everyone working in 
support of these programs to maintain complia nce with ap plicable legal documents and relevant authorities. Within the technical roles, there are two main 
areas of responsibility: collection and metadata I Hand the storage, presentation, and maintenance of the metadata. 




(TS//G I //NT) Some high-level examples of how key organizations support collection and metadata ■ find ude: 

to gain access to BR and P R/TT metad ata. 
|develops protocol processing software that supports the collection and metadata^ |and standardization. 

• Mission Capabilities (TD) integrates the BR and PR/TT protocol processing software into the larger exploitation systems. 

( TS//S I //NF ) | (and Mission Capabilities also support the storage, presentation, and maintenance aspects of the Bulk Metadata 

Programs, and some high-level examples include: 

• Mission Capabilities manages the BR and PR/TT repositories, as well as prepares the metadata for the analysts to use. 

• | provides reasonable assurance that the data is normalized and presented in a usable format and provides support to 
intelligence analysts. 
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(U) Authorization to Touch the Data 

(U) Analytical and technical personnel have different authorization to touch the metadata 
due to the nature of their work roles 
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(U) Authorization for Analytical Personnel 

Perform intelligence analysis (querying the 
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(U) Authorizations for Technical Personnel 

Create, test, and im plement tools to make this 
data easier for analytic personnel to use (TS/( |) 
ValidateJha^aieaua|jd^^DDropriately control analyst's access 
■ (TG//G I // B B) Perform processes to make the data usable 

0 Validation 
0 Defeat of col lection 
0 Processing 

0 Analysis of high-volume identifiers 

0 Maintenance of records to demonstrate compliance 



( T5//5 I //NF ) (Technical Character): As we have discussed throughout the course, the sensitivity of the data drives many of the policies and restrictions that 
control access to the BR and PR/TT bulk metadata. However, because of the different roles and responsibilities of analytical and technical personnel, both 
have different authorizations to touch the metadata. Recall from Module 1 we defined 'touching the data" as any form of data handling that creates an 
opportunity for a violation of the FISC Orders to occur. These activities may include data acquisition, modifying/preparing the data, querying, viewing results 
of the queries, and even oversight and compliance functions. 



OVSC 1205 MS 5C 



A): 



( TS//5 I //NF ) (HMC Character): Analytic personnel have authorization to touch the metadata to perform intelligence analysis. Analyst actions, such as 
querying the metadata for intelligence analysis purposes, must be done in a controlled way via tools designed to limit intelligence analysis access to RAS- 
approved identifiers and to the appropriate number of hops. Using these tools also provides reasonable assurance that these queries are tracked and 
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audited. 



Technical Personnel Info (audio file name OVSC_1205_M5_5040_T): 

( TS//5 I //NF ) (Technical Character): Technical personnel create, test, and implement tools to make this data easier for analytic personnel to use, while 
validating that safeguards appropriately control analysts' access to the bulk metadata. Additionally, technical personnel may access the metadata to 
perform those processes needed to make the metadata usable for inteNiaenceana lysis. These processes may include metadata validation; the defeat 
of the collection, processing, or analysis of metadata associated with I I identifiers; and the maintenance of records to demonstrate 

compliance with the terms of the authority. 



(T G //G I //NTH i^rder to do this work effectively, technical personnel are allowed to access the metadata using identifiers that are not RAS-approvecHr^he 
case of JJ^J^JJ identifiers, technical personnel may use non-R AS -approved identifiers to query the metadata to confirm if the identifier is a| 

(identifier and thus should not be included for target analysis. They may then share the identifier and the fact that it is a | (identifier 

with authorized personnel. However, no other information resulting from such queries can be used for intelligence analysis purposes. 



( TS//S I //NF ) Technicah^ersonnel must take great care with their responsibilities because they may be accessing the data through tools that do not have 
safeguards, such as | |that impose restrictions and minimize the chances of a violation of the FISC Orders. As a result we need to maintain 
boundaries between technical and analytical personnel, and be crystal clear as to the circumstances under which the two groups can interact 



TOP SCCRET//S I //NOrORN 
Page 5 of 10 



TOP GHCRi:T//G I //NOrORN 



DATE/PREPARER: SLS 



Topic 

(U) Interaction Between 
Analytical and Technical 
Personnel 



Home 



Page Classification 

TOP SECRET//S I //NOFORN 



Exit 



Glossary 



Screen Number 
5 of 8 



Back 



Next 



FRAME ID: 5050 



NEXT FRAME ID: 5060 



(U) Interaction Between Analytical and Technical Personnel 

(U) (Begin with image of analytical and Technical Character sitting at a table, then provide a close up of the 
Technical Character) 

( T5//5 I //NF ) All interactions must be based on RAS-approved identifiers and those results found within the 
number of hops authorized for intelligence analysis purposes 
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( TS//S I //NF ) (Technical Character): As we just discussed, analytical and technical personnel have different authorizations to touch this metadata. 
Because of these differe nt authorizati ons, we must be careful when the two types of personnel are interacting with regard to this metadata. Specifically, 
outside of the sharing of | | identifiers for defeat purposes, technical personnel should only be providing analytical personnel information 

under certain conditions. 

( TS//S I //NF ) (HMC C haracter): Som etimes, when analyzing the results of intelligence analysis queries, one or more of the specific results may seem out 
of the ordinary. Is it a | | identifier that was overlooked? Is the identifier misnormalized? Is there something that just seems out of place? Or 

perhaps there is a particular data field in your results that you don't understand. In such instances, intelligence analysts may require assistance from 
certain technical personnel responsible for data integrity functions. 

( TS//S I //NF ) (Technical Character): In these instances, technical personnel may assist authorized intelligence analysts, but any and all assistance must 
be based on RAS-approved identifiers and those results found within the number of hops authorized for intelligence analysis purposes. Essentially, 
when providing information to analytical personnel in these circumstances, the technical personnel must abide by the rules for the analytical personnel. 

( TS//S I //NF ) (Technical Character): In the end, all personnel have a vested interest and shared responsibility in ensuring that only the most accurate 
intelligence information is reported to customers, while abiding by the policies and requirements in place for this metadata. 
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(U) Knowledge Check 

1. ( TS//5 I //NF ) TRUE or FALSE: Technical personnel and analytic work roles have the same authorization to 
touch the bulk metadata. 

a) TRUE 

b) FALSE 

2. ( TS//5 I //NF ) The Analytic Work Role includes these functions: intelligence analysts who query the data, 
intelligence analysts who can view the results of intelligence analysis queries, and . 

a) Mission Capabilities (TD) 

b) 

c) Homeland Mission Coordinators (HMC) 

d) j^^^^^^^^^^^^^ 

3. ( TS//S I //NF ) The Technical Work Roles are comprised of two general areas of responsibility including 1) 
and 2) _. 

|2) reviewing RAS nominations 



a) 1) collection and metadata I 

b) 1) collection of content, 2) storage, presentation, and maintenance of the metadata 

c) 1) reviewing RAS nominations, 2) working with the telecommunications partners 

2) storage, presentation, and maintenance of the 



d) 1) collection and metadata | 
metadata 



(U) 



(Technical Character): Let's make a few notes in our travel journal and see what we remember from this topic. 
ANSWERS: 

Question 1. ( TS//S I //NF ) Correct! The answer is b) FALSE. Technical personnel have authority to make the metadata usable for intelligence analysis, while 
analytical personnel can only touch the bulk metadata for intelligence analysis purposes using RAS-approved identifiers within the authorized number of 
hops. 

( TS//S I //NF ) Incorrect. The correct answer is b) FALSE. Technical personnel have authority to make the metadata usable for intelligence analysis, while 
analytical personnel can only touch the bulk metadata for intelligence analysis purposes using RAS-approved identifiers within the authorized number of 
hops. 
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Question 2. ( T5//S I //NF ) Correct! The correct answer is c). The Analytical Work Role includes analysts and Homeland Mission Coordinators (HMC). 
( TS//S I //NF ) Incorrect. The correct answer is c). The Analytical Work Role includes analysts and Homeland Mission Coordinators (HMC). 

Question 3. (TG//G I //NO Right! The correct answer is d). The Technical Work Roles are comprised of two general areas of support including collection and 
metadata | l as we 'l as storage, presentation, and maintenance of the metadata. 

(TS//SI//NF) Incorrect. The correct answer is d). The Technical Work Roles are comprised of two general areas of support including collection and 
metadata ^^^^^B as well as storage, presentation, and maintenance of the metadata. 
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(U) Knowledge Check 

4. (T5//SI//NF) staff have access to the bulk metadata in order to prepare the metadata for 
the analysts touse^^^^^^^^^ 

a) | 

b) Mission Capabilities (TD) 

c) Analytical 

d) Office of General Counsel (OGC) 

5. (TS//SI//NF) If an intelligence analyst seeks assistance from technical personnel, technical personnel 

a) can query the metadata to confirm the analyst's results and point out potentially noteworthy 
contacts at the third or fourth hop 


GRAPHIC/AV: 


b) should explain that they are unable to assist in any way, except to identify] 

identifiers 

c) may offer assistance, but must be cautious that any results shared or discussed are 
based on a RAS-approved identifiers and those results that fall within the number of hops 
authorized for intelligence analysis purposes 

d) should provide whatever assistance is needed, but make a note of it in case anyone in 
management has questions later 

e) should decline to assist because technical personnel should not assist intelligence analysts 


(No audio or transcript on this page) 


Question 4. (TS//5I//NF) Correct! Mission Capabilities staff has access to the bulk metadata in order to prepare the metadata for the analysts to use. 
(T5//5I//NF) Incorrect. The correct answer is b). Mission Capabilities staff has access to the bulk metadata in order to prepare the metadata for the analysis 
to use. 

Question 5. (TS//SI//NF) Correct! If an intelligence analyst seeks assistance from technical personnel, technical personnel may offer assistance, but 
must be cautious that any results shared or discussed are based on RAS-approved identifiers and those results that fall within the number of hops 
authorized for intelligence analysis purposes. 

(TS//SI//NF) Incorrect. The correct answer is c). If an intelligence analyst seeks assistance from technical personnel, technical personnel may offer 
assistance, but must be cautious that any results shared or discussed are based on RAS-approved identifiers and those results that fall within the 
number of hops authorized for intelligence analysis purposes. 
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(U) Summary 

(U) Now that you have completed this module you should be able to: 

• (U) Compare and contrast the analytical and technical work roles 

• (U) Identify analytical and technical personnel's authorization to touch the data 

• (U) Identify how the authorities impact interactions with other roles and the data 


(U) (Technical Character): Now that we have completed this part of our road trip, you should be able to: 

• (U) Compare and contrast the analytical and technical work roles 

• (U) Identify analytical and technical personnel's authorization to touch the data 

• (U) Identify how the authorities impact interactions with other roles and the data 

(TS//5I//NF) (Technical Character): Now that you are aware of the various roles that support the BR and PR/TT Programs you will move on to your role- 
specific module that will go into additional detail on topics relevant to your responsibilities. 
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(U) Module 6 

(U) The Analytical Work Role 

(U) This module will enable you to: 

• (TS//S I //NF) Identify how BR and P R/TT fit into the analytic workflow 

• (TS//S I //NF) Recognize how BR and PR/TT authorities apply to real-life scenarios 
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( TS//5 I //NF ) (OGC Attorney): Throughout the first five modules of our course, we have discussed the BR and PR/TT Orders and the policies and 
procedures NSA has implemented to provide reasonable assurance of compliance with the Orders. We also have looked at the community of people and 
the work roles that are involved across the Enterprise to support that aspect of the mission. 



( TS//5 I //NF ) (HMC Character): This part of ourtrip is designed specifically for anyone working in an analytical role, or supervising staff in an analytical role, 
in support of the BR and PR/TT Bulk Metadata Programs. In particular we will discuss facets of BR and PR/TT that are of interest to analysts and HMCs. 
This module will enable you to: 

• ( T5//5 I //NF ) Identify how BR and PR/TT fit into the analytic workflow 

• ( T5//5 I // NF-) Recognize how BR and PR/TT authorities apply to real-life scenarios 
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( TS//S I //NF ) BR and PR/TT Programs enable NSA to fill collection gaps left by our other 
authorities 
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images/graphics pertinent to trie Zazi 
story). 

( T5//5 I //NF ) Graphic showing the portfolio 
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highlighted. Possible video footage of the 
arrest. 

( TS//5 I //NF ) (HMC Character): In Module 1, we mentioned that in order to gain comprehensive insight into a target's activities, it is often necessary to 
leverage multiple authorities and tools. CT targets have maintained an ongoing desire to conduct attacks within the United States. Given the unique U.S.- 
focus of the BR and PR/TT Programs, NSA is able to fill collection gaps left by our other authorities. 

( TS//S I //NF ) To illustrate how these various authorities can complement each other to fill critical gaps, as well as to show how BR and PR/TT fit into the 
analytic workflow, we'll step through the example of Najibullah Zazi and the New York subway plot 
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( T5//5 I //NF ) (HMC Characte r): ^^^^^^^^^^^^^^^^^^^^^^^J, CT analysts discovered a Pakistan-based email address associated with^^^^Jj 

operations | | the 

tasked the address to FAA 702 and reviewed the subsequent traffic on a regular basis. 

( T5//5 I //NF ) In Fall of 2009, one particular piece of content collection obtained from FAA 702 revealed an email exchange between a Pakistan-based target 
and an unknown individual suggesting that an unspecified terrorist operation was about to take place. Within this email, the analyst also discovered what 
appeared to be a U.S. -based phone number that was missing the country |code^ 



Comment [al]: Graphic of 2 terrorists sending 
email to each ottier, show email indicating threat and 
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NSA reported the suspicious activity and minimized U.S. phone number in a standard EGRAM. After 
receiving the unminimized U.S. phone number through NSA's Identity Release process, the FBI learned that the user of the unknown email address and 
owner of the phone number was a Colorado-based individual named Najibullah Zazi. FBI immediately started an investigation into Zazi's activities^ 



Commen^a2]: Maybe show report or something 
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( TS//S I //NF ) 




|U.S. person Na jibullah Zazi is the user of I 

| According to SIGINT reporting 
|a Pakistan-based al-Qa'ida (AQ) facilitator, 

Ireceived an email from Najibullah Zazi on 6 




Zazi also provided his 



Iphone number. 



( TS//5 I //NF ) (HMC Character): Simultaneously, to gain a fuller picture of Zazi's contacts, an NSA CT analyst submitted a RAS-approval reques t to an HMC 
on Zazi's phone number and email address. Recall from Module 3 that, in order to meet the RAS standard, an identifier must be tied to specific^ 

| In this case, the analyst met the RAS standardb^gasincnheiustificabon on the fact that Zazi was in direct 
communication with the Pakistan-based email address used by a member of ( (Because Zazi is a U.S. person, after the RAS 
requests on Zazi's identifiers were reviewed by an HMC, they were then sent to OGC, who performed a First Amendment review and gave the final 
lapprovaL 



( TS//S I //NF ) When considering RAS, analysts should remember to include just the basic facts needed with supporting documentation, as was done in the 
Zazi case, and not clutter the justification with excess information or documentation. 



| Comment [a3]: Graphic of RASten-plate 

Comment [chr4] : With the RAS 'ten-plate' are 
we going to pull up the key items in text bubbles or a 
'cloud' al a the rainbow slide presentation? 
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( TS//5 I //NF ) (HMC Character): After the RAS requests were approved, using the BR and PR/TT modes of B HCT analysts began running federated 
metadata queries on the approved identifiers, as we discussed in Module 4. The analyst querying Zaz^sCojoradoohone number discovered that around 
the time thatZazi exchanged emails with theHJ HJhe had also contactedB MJjhone numbers. Using the 

guidance that we discussed in Module 4, the analyst determined thatZazi's contacts with these (■■■■numbers were unique to BR metadata. Based on 

this uniqueness, the analyst began drafting a report in accordance with the dissemination guideli we reviewed in Module 4. Before the report was 

released, the Chief of S 12 determined that the report met the CT Nexus criteria and approved its release 1 ^ 



Comment [a5]: Use one of screanshots showing 
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(TS//5 I //NF) Remember, even 'Tact of statements describing whatBR- or PR/TT-unique data was discovered are considered "query results" underFISC 
guidelines an d must be handled in accordance with the Court Orders. However, once formally disseminated to customers, it no longer requires the 

Iprotection and is treated as normal SIGINT analysis, as is the case with the example we have just described. 
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(U) Knowledge Check 

1. ( T5//5 I //NF ) In the Zazi scenario, analysts used E.O. 12333 and FAA 702 collection to support RAS. 
Which source(s) can be used to support RAS? 

a) (U) FBI reporting 

b) (U) Open source information 

c) ( T5//5 I //NF ) NSA FISA collection 

d) (U) All the sources above can be used 

2. ( T5//5 I //NF ) Why was toe RAS request for Zazi sent to OGC for a F irst Amendment review? 

a) (TS//S I //NF) All RAS requests go to OGC for a First Amendment review 

b) (TS//S I //NF ) Zazi is a U.S. person 

c) (TS//SI//NF ) Zazi is a member of al-Qa'ida or an associated terrorist group 

d) ( TS//SI//NF ) The RAS determination was a close call 



(U) (HMC Character): Let's make a few notes inourtravel journal and check to see what you remember from tois topic! 



Question 1. (U //FOUO ) Correct! Any information that is lawfully in our possession may be used to support a RAS determination. 

(U //FOUO ) Incorrect, toe correct answer is d). Any information toat is lawfully in our possession may be used to support a RAS determination. 

Question 2. (U //FOUO ) Correct! A First Amendment review is only necessary when toe identifier is believed to belong to a U.S. person. 

(U //FOUO ) Incorrect toe correct answer is b). A First Amendment review is only necessary when the identifier is believed to belong to a U.S. person. 
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3) (TS//SI//NF) In this scenario, information was discovered that was unique to the BR authority. If that same 
information had also been discovered in E.O. 12333 collection, a CT Nexus determination would still need to 
be made in order to disseminate that information because the information was in the BR repository. 


NEXT FRAME ID: 6100 


a) (U)True 

b) (U) False 








4) (T5//5I//NF) Why are students without^ | allowed to learn that Zazi had contact with other New 
York numbers? ^^^^^^^^^^ 
a) (T5//5I//NF) That information is not specific enough to qualify as | 


BACK FRAME ID: 6080 


ALT TAG: 


b) (T5//5I//NF) The information is over one year old 

c) (TS//SI//MF) The information has been previously disseminated outside of NSA 




d) (TS//SI//NF) It is being shared for training purposes 




GRAPHIC/AV: 








(No audio or transcript on this page) 




Question 3. (T5//5I//NF) Correct! If the same information is discovered through another source, neither the BR nor PR/TT rules and requirements apply. 
(TS//SI//NF) Incorrect. The correct answer is b) (False). Neither the BR nor PR/TT rules and requirements apply if the same information is discovered 
through another source. 


Question 4. (TS//SI//NF) Correct! The information can be disclosed to those without | | because it has previously been disseminated outside 


of NSA. ^^^^^^^ 

(TS//5I//NF) Incorrect The correct answer is c). The information can be disclosed to those wiUiout| |only because it has previously been 


disseminated outside of NSA. 
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(U) Practice Scenario 1 

(T5//SI//NF) You are a| (cleared analyst who, through PR/TT metadata analysis of seeds associated 
with a high value CT target has identified a PR/TT-unique direct contact - email address^ 

believed to be used by someone iiTYemen^ouarenotsure whether the identifier warrants further development as 
a target, but to find out you place | | in a tasking database to enable content collection from 
E.O. 12333 sources. This tasking database is widely available to all intelligence analysts in the SIGINT Production 
Chain. For this reason, you note in the comments field thatthis identifier was discovered through metadata analysis 
and is believed to be a direct contact of the high value CT target, but you deliberately avoid identifying the P R/TT 
metadata as the source of the identifier. Are your actions in compliance with the terms of the PR/TT Orders? 

(U) Please select the your answer: 

a) (T5//5I//NF) Yes, because you did not include the reference to PR/TT. 

b) (TS//5I//NF) No, because you failed to mark the source of the identifier as PR/TT metadata. 

c) (T5//5I//NF) Yes, because the results will be governed under E.O. 12333 rules and procedures. 

d) (TS//SI//NF) No, because you have shared a PR/TT-unique quervresul^vith a wide audience 
of intelligence analysts, many of whom do not hold current M Hcredentials. 


(U) (HMC Character): Now lets practic 


e what we have learned using a real-life scenario. Carefully read the scenario and then select the best answer. 


ANSWER: 

a) (TS//SI//NF) Incorrect The correct answer is d). No, because you have shared a PR/TT-unique query result with a wide audience of intelligence 
analysts, many of whom do not hold current ( ^credentials. 

b) (TS//SI//NF) Incorrect The correct answer is d). No, because you have shared a PR/TT-unique query result with a wide audience of intelligence 
analysts, many of whom do not hold current | | credentials. 

c) (T5//5I//NF) Incorrect The correct answer is d). No, because you have shared a PR/TT-unique query result with a wide audience of intelligence 
analysts, many of whom do not hold current | | credentials. 

d) (TS//SI//MF) Correct! The right answer is d). No, because you have shared a PR/TT-unique query result with a wide audience of 
intelligence analysts, many of whom do not hold current | ^credentials. 



TOP SECRET//S I //NOFORN 
Page ID of 12 



TOP SECRET//S I //NOFOR I M 



DATE/PREPARER: 



Topic 

(U) Summary 



Home 



Page Classification 

TOP S E C RET//S I//NOF O R N 



Page Number 
10 of 12 



Exit 



Glossary 



Back 



Next 



FRAME ID: 6100 



NEXT FRAME ID: 6110 



BACK FRAME ID: 6090 



ALT TAG: 



GRAPHIC/AV: 



(U //FOUO ) You should now be able to: 

• (TS//S I //NF ) Identify how BR and PR/TT fit into the analytic workflow 

• (TS//S I //NF ) Practice applying BR and PR/TT authorities in real-life scenarios 

(TS//S I//NF) If you have questions or wish to find out more, please contact yourj 
| leared manager or any of the following BR or PR/TT points of contact: 

OGC email alias: DL gc ops 
OGC Phone:| |or963-3121(s) 

OGC website: go GC 
HMCs email alias: DL CT HMC 

SID Oversight and Compliance email alias: DL SV42_all 



(U //FOUO ) (HMC Character): Now that we have completed this part of our road trip, you should be able to: 

• ( TS//S I //NF ) Identify how BR and PR/TT fit into the analytic workflow 

• ( TS//S I //NF ) Practice applying BR and PR/TT authorities in a real-life scenario 

( T5//5 I //NF ) (HMC Character): You are encouraged to reach out to youi'l (cleared manager or any of the points of contact listed here if you 

have any questions or if you want to find out more. Please remember that it is critical to our mission that we are 100% compliant with the requirements in 
the Court Orders especially with regards to collaborating, sharing, and disseminating this data through the course of your analysis work. You may review 
this course at any time and seek guidance from any of the points of contact listed here. 
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(U) PLEASE READ: Important Assessment Information 

• (U) You will view the questions in a separate Assessment Questions Document 

• (U) You will enter your responses in a separate QuestionMark online answer sheet 

• (U) You will have only one attempt to successfully complete the assessment 

• (U) Allow yourself sufficient time (approximately 30 minutes) to complete the assessment 

(U) To Complete the Assessment: 

• (U) Click the link to open the Assessment Questions Document 



(U) Go to the VUport SumTotal Content Player page, click on the Assessment link, and follow the 
instructions to complete the required exam 



Comment [SLS6]: Pleasemakethisalinkthat 
will open the Assessment Question pdf for 
Analytical Personnel (we will actually connect the 
link later). 



(U //FOUO ) (OGC Attorney): The final part of your trip will be to successfully complete the assessment for the course. Please be aware that for the 
assessment you will view the questions in a .pdf file and enter your responses in a separate QuestionMark online answer sheet Please be sure that you 
open the .pdf with the questions first before opening the QuestionMark online answer sheet You will have one attempt to complete the assessment Please 
allow yourself sufficient time (approximately 30 minutes) to complete the assessment 

(U //FOUO ) Please click the Assessment Questions Document link to open the .pdf question file and keep the window open. Then go to the VUport 
SumTotal Content Player page, click on the Assessment link on the left, and follow the instructions to complete the required exam. 
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(U) This module will enable you to: 
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- (TS//S I //N T ) - 1 dentify the various technical roles that support toe BR and PR/TT Bulk 
Metadata Programs 

(U) Identify toe responsibilities of each of toe technical roles 

(U) Recognize key points of the compliance certification process for mission 

systems and data flows 

( TS//S I //NF) P ractice applying BR and PR/TT authorities in real-life scenarios 
applicable to technical personnel 



(TG//G I //N r ) (OGC Attorney): During this part of our trip, we discuss several topics of particular interest to those of you in technical roles, or supervising 
staff in a technical role, supporting the BR and PR/TT Bulk Metadata Programs. It is important for you to remember that the essential support you provide 
enables all of the roles to perform their BR- and PR/TT-related work in compliance with applicable legal documents and relevant authorities. As we 
discussed in Module 5, because of this great responsibility, technical personnel have been given tremendous access to touch the data in order to make it 
available and usable for the analysts. 

(TS//5 I //MF ) (Technical Character): In this module we are going to discuss the authorizations, roles, and responsibilities of the Technical Personnel. This 
module will enable you to: 

• (TG//G I //NT) Identify the various technical roles that support the BR and PR/TT Bulk Metadata Programs 

Classified By: slsanc2 
Derived From: NSA/CSSM 1-52 
Dated: 20070108 
Declassify On: 20350501 
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• (U) Identify the responsibilities of each of the technical roles 

• (U) Recognize key points of the compliance certification process for mission systems and data flows 

• (T5//5I//NT) Practice applying BR and PR/TT authorities in real-life scenarios applicable to technical personnel 
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(T5//5I//MF) (Technical Character): In Module 5, we explained there are two major areas where technical support is providedfor the BR and PR/TT Bulk 
Metadata Programs. The first is the group of technical personnel who are responsible for the collection and metadata H process. The second is the 
group responsible for storage, presentation, and maintenance of the BR and PR/TT metadata. In the next few screens, we will describe in more detail these 
two main areas of responsibility. 
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(U) Collection and Metadata Extraction Support 




(U) Collection and Metadata 




(U) Mission C£*3atoilitj<E 



(U// rOUO) (Technical Character): Let's examine more closely the work roles res| 
category of technical staff currently includes the technical professionals in NSA's 




Mission 



Capabilities staff within the Technology Directorate (TD) organizations. As we proceed through this module you will find out more about the roles in each of 
these three organizations. 

(TG//G I //NT) Note that in addition to these key roles, there are other technical roles that are important to the implementation of these programs. These roles 
include individuals involved in the acquisition, processing, presentation, storage, retention, and support to operations which are authorized under the BR 
and PR/TT Orders. 
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Some of the rules that apply to Mission Capabilities staff within the Technology Directorate (TD) are to provide reasonable assurance that: 



m 



All of the metadata remains identifiable as PR/TT data 
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(U) Knowledge Check 1 

(U) Match the organization to its corresponding roles and responsibilities: 

1. (TS7 7?t#NEJ^taff in is responsible for developing th e I 

a) (U) Mission Capabilities 

b) I 

d) (U) Homeland Mission Coordinators 

is responsible for integrating the PR/TTl 
"Including conducting related testing prior to system 

a) (U) Mission Capabilities 

b) 




d) (U) Homeland Mission Coordinators 
3. (T5//G I //ND Staff in is responsible for] 




a) (U) Missio n Capabilities 
b) 
c) 

d) (U) Homeland Mission Coordinators 




(U) (Technical Character): Lefs make a few notes in ourtravel journal and check tD see what you remember from this topic! 
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(TG7/G I //Nr) (Technical Character): Now lefs discuss the work roles responsible for the storage, presentation, and 
metadata. This category of technical staff currently includes the technical professionals in Mission Capabilities and 



e BR and PR/TT 
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(U) Storage, Pr 



on, and Maintenance of the Metadata 



(U) Mission Capability 




(TS//SI//NF) Mission Capabilities is 
responsiblefor: 

• Developing maintaining, and operating 
repositories that store and present BR and 
PR/TT metadata 




(T5//5 I //N r ) S ome of the rul es that appl y tjo Mission Capabilities: 

• M ebadata must be maintained in secure NSA repositories 

• Data must be identifiable as B R or PR/TT 

• I mpl ement techni cal control s to prevent unauthori zed access 

• Restrict intelligence analysis queries to RAS-approved identifiers (eg. the EAR) 

• E nsure i ntd I i gence anal ysi s queri es remai n wi thi n authori zed number of hops 

• Createauditable records of all intelligence analysis queries 

• Destroy al I metadata before the end of the f i ve year authori zed retenti on peri od ( no 
exceptions!) 

• Changes to systems must be certified by theTD Compl i ance Off i ce before 
implementation 

• Automated queries are prohibited without approval 
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(TS//S I //NE) (Technical Character): You will recall that Mission Capabilities supports collection and metadata 




and other branches of Mission 



Capabilities support storage, presentation, and maintenance of the metadata. For Jhelatten the staff is typically database management and user interface 



(TD//G I//N T ) Some of the rules that apply to Mission Capabilities include: 

• Metadata must be maintained in secure NSA repositories 

• Data items must be identifiable as BR or PR/TT metadata 

• Implement technical controls to prevent unauthorized access 

• Implement technical controls to restrict intelligence analysis queries to RAS-approved identifiers (e.g. the EAR) 

• Implement technical controls to provide reasonable assurance that the results of intelligence analysis queries remain within the authorized number 
of hops 

• Create auditable records of all intelligence analysis queries 

• Destroy all metadata before the end of the five year authorized retention period (no exceptions for backup data) 




(TS//S I //N E-)-This staff will come in contact with human intelligible BR and PR/TT metadata. 




|tfiat store and present BR and PR/TT metadata, as well as 
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(U) Storage; Presentation, and Maintenance of trie Metadata 



(U) Miss on Capabilities 




(T S//SI//N F) Protocol Exploitation is 
responsiblefor: 

• Ensuring data is normalized and is 
presented in a usable for mat 

• Providing support tointel I igence analysts 



For B R , ■ H erf orms uni que f uncti ons i ncl udi ng: 

Normalizing 

Re/i ewi ng data to ensure records i ncl ude onl y data H 

Assist in ensuring that data to be presented to analysts will be in a usable format 

Providing operational support to intel I igence analysts; support is limited to RAS-approved identifiers 

wi thi n the authori zed number of hops 



laracter): As you for PRATT, ■ Bprovides support toH H f° r 

BR, ■ Bassists in ensuring accurate representation and integrity of the metadata. In this contex t M^M^M^M^MM performs both a 

tech uppoiting role for intelligence analysts. Because of this dual role, J | must apply the rules governing the specific 

function it is performing at the time. WhemjerfomTinc^aJechnical role, the technical rules apply which allow broader access to the data. However, when 
supporting the intelligence analyst theH I staff must operate within the same rules applicable to the intelligence analyst which are more 
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restrictive. 



US//SI//NI-) For BR, | 



| performs unique functions to include: 
Normalizing all of the disparate data formats ^^^^^^^^^^^^^^^^^^^H 

Reviewing the data to validate that the records include only data| 

Assist in ensuring that the data to be presented to the analysts will be in a usable format 

Providing operational support as necessary to intelligence analysts; support is limited to RAS-approved identifiers within the authorized number of 
hops 
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(U) Knowledge Check 2 

4. (T5//5I//NF) Which one of these is not one of the roles and responsibilities of the technical personnel? 

a) (U//FOUO) Manipulating and validating the metadata to make it usable for intelligence analysis 
purposes 

b) (T5//5I//NT) Developing new tools to support querying of BR and PR/TT metadata 

c) ( G //G I //REL) Running an intelligence analysis query using a RAS-approved identifier for an analyst 
who is experiencing problems recreating their query results 

d) (S//G I //RCL) R unning an intelligence analysis query using a non-RAS -approved identifier for 
an analyst who is experiencing problems recreating their query results 

e) (U) Both C and D 

5. (TS//5I//NF)| |jrovides support to the BR program by doing the following (check all 
that apply): ^^^^^^^^^^^^^^^^ 

a) (U) Normalizing all of the disparate data formats j^^^^^^^^^^^^^^^H 

b) (U) Reviewing the data to validate that the records include data I 



c) (U) Ensuring metadata is maintained in secure NSA repositories. 

d) (U) Assist in ensuring that the data to be presented to the analysts will be in a usable format 

e) (U) Destroy all metadata before the end of the five year authorized retention period (no exceptions 
for backup data 

f) (S//SI//REL) Providing operational support as necessary to intelligence analysts on RAS- 
approved identifiers within the authorized number of hops 



nt and user interface professionals in 



6. (TG//5 I //ND Database 
maintain, and operate the | Ht na t store and present BR and PR/TT metadata, and develop 
algorithms/processes that prepare, optimize, and characterize the metadata for analytic utilization. 

a) 

b) 

c) 

d) (U) Homeland Mission Coordinators 



develop, 



(U) (Technical Character): Lefs check what you remember from this topic! 



Question 4. (TS//S I //Nr) Correct! Running an intelligence analysis query using a non-RAS-approved identifier for an analyst who is experiencing problems 



TOP 5ECRET//5 I //NOFORN 
Page 18 of 30 



T OP 5bCKLT//5 l //r'JOrOKN 



recreating their query results is not one of the roles and responsibilities of the technical personnel. 



(T5//GI//NO Incorrect The correct answer is d). Running an intelligence analysis query using a non-RAS-approved identifier for an analyst who is 
experiencing problems recreating their query results is not one of the roles and responsibilities of the technical personnel. 



Question 5. (TS//5I//NF) Correct! J ^provides support to the BR program by doing the following: 

a) (U) Normalizing all of the disparate data formats ^^^^^^^^^^^^^^^^^^^^^m 

b) (U) Reviewing the data to validate that the records include data | 

d) (U) Assist in ensuring that the data to be presented to the analysts will be in a usable format 

f) (S//SI//REL) Providing operational support as necessary to intelligence analysts on RAS-approved identifiers within the authorized 
number of hoo^^^^^^^^^ 
(TS//G I //NI~) Incorrect^ | provides support to the BR program by doing the following: 

a) (U) Normalizing all of the clisiiarate data formats ^^^^^^^^^^^^^^^^^^^^^h 

b) (U) Reviewing the data to validate that the records include data | 

d) (U) Assist in ensuring that the data to be presented to the analysts will be in a usable format 

f) (S//SI//REL) Providing operational support as necessary to intelligence analysts on RAS-approved identifiers within the authorized 
number of hops 

Question 6. (T0//G I //NO Correct! Database management and user interface professionals in Mission Capabilities develop, maintain, and operate 
^store and present BR and PR/TT metadata, and develop algorithms/processes that prepare, optimize, and characterize the metadatal 

(TC //□ I //r J r ) Incorrect The correct answer is a). Database management and user interface professionals in Mission Capabilities develop, maintain, and 
operate the^^^^^^Btha^tore_and present BR and PR/TT metadata, and develop algorithms/processes that prepare, optimize, and characterize the 
metadata 
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(U) The Compliance Certification Process 

(U//FOUO) Compliance certification is a mandatory check for all systems handling U.S. 
person or FISA data 

(U) Guidelines governing the certification process are maintained by theTD Compliance 
Office 

(U) Compliance should be integrated into the development process 


(T5//5 1//N r ) (Technical Character): Next we will discuss the compliance certification process used by technical personnel who develop mission 
technologies to include those supporting the BR and PR/TT Programs. Compliance certification is a mandatory check forall systems handling U.S. person 
or FISA data. Guidelines governing the certification process are maintained by the TD Compliance Office. This process supports compliance with the 
applicable laws and authorities and supports the NSA Way. The NSA Way is a unified framework for building large (or small), complex, primarily software 
systems that meet the diverse needs of NSA missions. An important point is that compliance should be integrated into the development process. 
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NEXT FRAME ID: 7150 



(U) Following the Compliance Certification Process 

(U) The goal of the compliance certification process is to integrate compliance into the 
development phase 
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(TS//S I//N F ) (Technical Character): The goal of the compliance certification process is to integrate compliance into the development phase. The gates 
shown in the compliance process represent distinct requirements that must be satisfied in order to provide reasonable assurance of compliance. The 
architects of the new technology develop engineering documents to support these requirements. The TD certification group reviews the artifacts to verify 
the compliance process requirements are being met 



(T5//3 I //NT ) The compliance certification process begins by registering inl 
browser. Once registration is complete, you will receive a requirements pa 



I Access the site by typing 



(U//FtX4C0 Compliance is an ongoing process. Any change or update to previously certified software requires recerrj 
words, if you develop a modification or upgrade to the software, then you need to register the software modification in 
recertification process. 
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(T5//0I//Nr) Formal approval is required for all new and/or different BR and PR/TT systems. Under no circumstances can a change be made to a software 
system (even for testing purposes) without going through the compliance certification (or recertification) process. 
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(U//FOUO) The goal of dataflow governance is to provide reasonable assurance of 
accountability and compliance for NSA mission data as it moves throughout NSA systems 



(U//FOUO) Triggers for entering the dataflow governance process include (but are not 
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(T0//G I //NT) (Technical Character): The Collection Strategies and Requirements Center (CSRC) is responsible for dataflow governance, which provides 
reasonable assurance of accountability and compliance for NSA mission data as it moves throughout NSA systems. This is critical to protect the data, and 
when we are talking about volumes of U.S. person data you can understand why this is so important 

(T5//G I //Nr) The process begins by submitting a dataflow request (usually done by the system builder or access owner) for a new dataflow solution. Then 
some level of research is needed to determine tine type of request and associated needs. Once the requirements are determined, a new processing 
capability may be developed, or an existing flow may be reconfigured to meet the new requirement The solution must then be tested and obtain official 
sign-off at which time CSRC authorization to operate would be issued. 

(U/TF^SUOHiTCieiTeral^ricia^rsfo dataflow governance process include (but are not limited to): 

• Replacing an existing repository 

• Inserting a process or system into the flow 

• Adding a new mission element 

• Legacy migration (moving an existing unmanaged flow to a managed flow) 

(TS//G I //Nr) Formal approval is required for all new and/or different BR and PR/TT data flows. Under no circumstances can a change be made to a data 
flow (even for testing purposes) without going through the dataflow governance process. 

(U// FOUO) To find out more about the dataflow process, please refer to the Dataflow webpage by typing 'go dataflow' in your web browser. 
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(U) Knowledge Check 3 

7. (TG//G I //Nr) The compliance certification process for new systems is triggered by 



a) (U) Entering a ticket intoH 

b) (U//FOUO) Contacting NSA Way Team 

c) (U//FOUO) Entering the new software or system into | 

d) (U) All of trie above 

8. (TS//SI//N^^^^^yj^Jo^^m^^^^^^yje^on for entering the dataflow governance process? 

a) I 

b) (U) Replacing an existing repository 

c) (U) Inserting a process or system into trie flow 

d) (U) Modifying a bulk metadata query 

e) (U) Moving an existing unmanaged flow to a managed flow 

9. (T5//5I//NT) Before an analytic software upgrade is released on a system that handles BR or PR/TT data, 
the developers would need to in order to remain compliant 

a) (U) contact the CSRC and undergo conjjMancerecertrfication 

b) (U) register the software release inH Hand undergo compliance recerb'fication 

c) (U) obtain OGC approval ^^^^^^^^^^H 



d) (U) register your system with ODOC 



(U) (Technical Character): Lefs make a few notes in ourtravel journal and check to see what you remember from this topic! 




Correct! The compliance certification process for new systems is triggered by entering the new software or system in 
ct The correct answer is c). The compliance certification process for new systems is triggered by entering the new software or system in 

Question 8. (U//FQIJQj Correct! Modifying a bulk metadata query is not a reason for entering the dataflow governance process. 
(U#F-QUQJJncorrect. The correct answer is d). Modifying a bulk metadata query is not a reason for entering the dataflow governance process. 

Question 9. (U/ /FOUO) Correct! Beforear^nalvtic software upgrade is released on a system that handles BR or PR/TT data, the developers would need to 
register the software release in I Hand undergo compliance recertification in order to remain compliant. 

(U //rOUO ) Incorrect The correc^^^^^^^^ ^Before an analy tic software upgrade is released on a system that handles BR or PR/TT data, the developers 
would need to register the software release in HJIHJ^BBand undergo compliance recertification in order to remain compliant 
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(U) Practice Scenario 1 ^^^^^^^^H 

(T5//5 1 //N T ) You are one of the | | cleared technic^^^^^^^^^^ponsible for metadata management 

within NSA's metadata repositories. You are working with otherM M-cleared developers on new query 

processes and tools. You | |a set of properly marked recor y your team for development 

purposes from the P R/TT metadata. This set of P R/TT metadata records is stored on a physically isolated system 
within NSA's secure network and is accessible only to the members of your team. Are your actions in 
compliance with the terms of the PR/TT Orders? 

(U) Please select the BEST answer: 

a) (TS//0 l //Nr) Yes, because the PR/TT Orders explicitly authorize properly trained technical 
personnel to develop and test new technologies to be used with the PR/TT metadata. 

b) tT5//5l//Mr) No, because the PR/TT Orders prohibit the use of new query processes against any of 
the PR/TT metadata. ^^^^^^^^m 

c) (T3//3I//Nf") Yes, because the| |PR/TT metadata records still carry the unique 
markings and sof^^re^ontoolson the physically isolated system to restrict access to 
those records to| | cleared personnel. 

d) (U) None of the above are correct 



(U) (Technical Character): Now lets practice what we have learned using real-life scenarios. Carefully read the scenario and then select the best answer. 



ANSWER: 

a) (T5//SI//Nr) Incorrect This statement is accurate, but this is not what makes your actions compliant The correct answer is c). Yes, because the 

^^R/TT metadata records still carry the unique markings and software controls on the physically isolated system to restrict access to 
those records '"I Reared personnel. 

(TG//G I //ND Inco rrect The current Court Orders authorize NSA to develop new query processes. The correct answer is c). Yes, because the 

J R/TT metadata records still carry the unique markings and software controls on the physically isolated system to restrict access to 
those records to | (cleared personnel. ^^^^^^^^^^H 

c) ( I V/UI//NI ) Correct! The best answer is c). Yes, because thel HpR/TT metadatajgCQrdsstjM carry the unique markings and 
software controls on the physically isolated system to res trie e records tol H-cleared personnel. 

d) (TS//G I //Nr) Incorrect The correct answer is c). Yes, because toe^^^^^^^^^JpR/TTnTetexjaterecords still carry the unique markings and 
software controls on the physically isolated system to restrict access to those records to H H-cleared personnel. 
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(U) Practice Scenario 

(TG//G I //NT) Y ou are a I H-cleared developer of contact chaining analytic tools. Your 

management chain has requested a briefing to demonstrate your progress on the latest version of the tool. 
You provide the briefing, which includes screen shots of the tool and query results generated by the tool. Are 
your actions in compliance with the Orders? 

(U) Please selectthe BEST answer: 

a) (U/ /FOUO) No, unless all of those onvourdevetogmentteam and all those who 
attended your briefing held current! ^clearances. 

b) (U) No, because the Court Orders do not permit testing of tools under development using 
real data. 

c) (U) Yes, as long as the query results shared during the briefing are never used for 
intelligence analysis purposes. 

d) (U) None of the above are correct 



ANSWER: 

a) (U) Correct! This is the best answer. You cannot provide a demonstration unless all of the individuals who attended the briefing have 
completed the required training and received the necessary accesses. 

b) (U/7FQJ 4P) Incorrect Th e correct answer is a). No, unless all of those on your development team and all those who attended your briefing held 
current| ^clearances. 

c) (U//FT>WO^nconaec^The correct answer is a). No, unless all of those on your development team and all those who attended your briefing held 
current I Hclearances. 

d) (U//F*Q yQ) Incorrect Th e correct answer is a). No, unless all of those on your development team and all those who attended your briefing held 
current H ^clearances. 
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(U) Practice Scenario 3 

(TS//SI//MF1 You are one of theH M-cleared technical personnel responsible for metadata 

management within NSA's metadata repositories. You are responsible for the maintenance of backup 
systems and Continuity of Operations (COOP) planning and implementation. You have contro^ver the 
backup tapes that hold PR/TT metadata collected since the inception of the PR/TT authority J ^ In 
accordance with your COOP plans, you know that if a disaster strikes and NSA's online metadata 
repositories are destroyed, you could use these backup tapes to repopulate the repositories with PR/TT 
metadata. Although the backup tapes contain information older than five years, the processes you would 
employ to repopulate the online analytic metadata repositories would select only metadata collected within 
the last five years. Is your maintenance of backup tapes holding PR/TT metadata collected more than five 
years ago in compliance with the terms of the PR/TT Orders? 

(U) Please select the BEST answer: 

a) (TG7/5 l //NO Y es, because the older-than-five-years PR/TT metadata on the backup tapes 
will never be available for intelligence analysis purposes. 

b) (TS//SI//NF ) Yes, because the PR/TT Orders specifically authorize NSA to maintain backup 
tapes of the PR/TT metadata. 

c) (TS//S I //NF ) No, because the PR/TT Orders mandate the destruction of the PR/TT 
metadata no later than five years after its initial collection, with no exception for 
metadata on backup tapes. 

d) (U) None of the above are correct 



ANSWER: 

a) ( T0//0 l //Nr ) Incorrect The correct answer is c). No, because the PR/TT Orders mandate the destruction of the PR/TT metadata no later than five 
years after its initial collection, with no exception for metadata on backup tapes. This is different from other authorities, for example FAA 702 does 
not require the destruction of data in the archives. 

b) ( TG//G I //NF ) Incorrect The correct answer is c). No, because the PR/TT Orders mandate the destruction of the PR/TT metadata no later than five 
years after its initial collection, with no exception for metadata on backup tapes. 

c) (TS//SI//M F) Correct! This is the best answer. No, because the PR/TT Orders mandate the destruction of the PR/TT metadata no later than 
five years after its initial collection, with no exception for metadata on backup tapes. 

d) (TS//S I //NT) Incorrect The correct answer is c). No, because the PR/TT Orders mandate the destruction of the PR/TT metadata no later than five 
years after its initial collection, with no exception for metadata on backup tapes. 
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(U) Now that you have completed this module you should be able to: 

• (TG//5 I //NO Identify the various technical roles that support the BR and P R/TT Bulk 
Metadata Programs 

• (U) Identify the responsibilities of each of the technical roles 

• (U) Recognize key points of the compliance certification process for mission 
systems and data flows 

• (TG//G I //NO Practice applying BR and PR/TT authorities in real-life scenarios 
applicable to technical personnel 

(U// rOUO> If you have questions or wish to find out more, please contact your manager or 
any of the following BR orPR/TT points of contact: 

TD Compliance Office website: go td compliance 

email alias:| 

Phone: | 
OGC website: go GC 

Oversight and Compliance email alias: DL SV42_all 



(TG//G I //NO (Technical Character): As we stated earlier in the course, the bulk metadata includes sensitive data that must be protected accordingly. By 
nature of the kinds of technical support provided to the BR and PR/TT programs, technical personnel have the authority and unrestricted access to touch 
unminimized/unevaluated (or raw), and very sensitive data (that contains a lot of U.S. person identifiers). Remember, we need to maintain a clear 
distinction between the roles of technical and analytical personnel. All personnel are held to a high standard of integrity, but in your technical role you must 
be particularly cautious because the tools you work with do not provide the same safeguards as those tools used by the analytical personnel. 
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( TS//G I //Mr) In conclusion, it is your responsibility to keep the BR and PR/TT information within the confines of those who have the proper authorizations to 
touch and view the data. 

(U) Now that we have completed this part of our road trip, you should be able to: 

• ( TG//5 I //Pdl~ ) Identify the various technical roles that support the BR and PR/TT Bulk Metadata Programs 

• (U) Identify the responsibilities of each of the technical roles 

• (U) Recognize key points of the compliance certification process for mission systems and data flows 

• (TD//fj l //Nr) Practice applying BR and PR/TT authorities in real-life scenarios applicable to technical personnel 

(U) You are encouraged to reach out to your management or to any of the points of contact listed here if you have any questions or if you want to find out 
more. 
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(U) PLEASE READ: Important Assessment Information 

• (U) You will view the questions in a separate Assessment Questions Document 

• (U) You will enter your responses in a separate QuestionMark online answer sheet 

• (U) You will have only one attempt to successfully complete the assessment 

• (U) Allow yourself sufficient time (approximately 30 minutes) to complete the assessment 

(U) To Complete the Assessment: 

• (U) Click the link to open the Assessment Questions Document; 



(U) Go to the VUport SumTotal Content Player page, click on the Assessment link, and follow the 
instructions to complete the required exam 



Comment [SLS1]: Pleasemakethisalinktnat 
will open the Assessment Quest] on pdf for 
Analytical Personnel (we will actually connect the 
link later). 



(U //rOUO - ) (OGC Attorney): The final part of your trip will be to successfully complete the assessment for the course. Please be aware that for the 
assessment you will view the questions in a .pdf file and enter your responses in a separate QuestionMark online answer sheet Please be sure that you 
open the .pdf with the questions first before opening the QuestionMark online answer sheet You will have one attempt to complete the assessment Please 
allow yourself sufficient time (approximately 30 minutes) to complete the assessment 

(U/ /rOUO) Please click the Assessment Questions Document link to open the .pdf question file and keep the window open. Then go to the VUport 
SumTotal Content Player page, click on the Assessment link on the left and follow the instructions to complete the required exam. 
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(U) MODULE 1 

(TS//SI//NF ) Business Records (BR) and Pen Register Trap and Trace (PR/TT) Bulk 
Metadata Programs 

(U) This module will enable you to: 

• (TS//S I //NF) Identify the purpose of the BR and PR/TT Bulk Metadata Programs 

• (TS//S I //NF) Identify the Foreign Powers covered by the BR and PR/TT Foreign 
Intelligence Surveillance Court (FISC) Orders 

• (TS//S I //NF) Contrast the differences in the authorities granted between BR FISC 
Orders and PR/TT FISC Orders 

• (TS//S I //NF) Recognize the role of the Bulk Metadata Programs in the context of the 
broader set of SIG I NT authorities 



( T5//5 I //NF ) (OGC Attorney): During the first part of our road trip we will discuss the Business Records (BR) and Pen RegisterTrap and Trace (PR/TT) 
Bulk Metadata Programs at a high level. As we progress on our road trip, we will discuss various aspects of the authorities granted by the Foreign 
Intelligence Surveillance Court (FISC) which support the BR and PR/TT programs and the policies that NSA implements to provide reasonable assurance 
that we are compliant with these authorities. 
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(U) This module will enable you to: 

• ( TS//S I //NF ) Identify the purpose of the BR and PR/TT Bulk Metadata Programs 

• (TS//SI//NF) la^nWytiTe^^BForeign Powers covered by the BR and PRATT Foreign Intelligence Surveillance Court (FISC) Orders 

• (TS//SI//NF)( | in the authorities granted between BR FISC Orders and PR/TT FISC Orders 

• ( TS//S I //NF ) Recognize the role of the Bulk Metadata Programs in the context of the broader set of SIG I NT authorities 
Scroll over text for foreign powers: 

( TS//S I //NF ) Under the FISA statute, a foreign power can include "a group engaged in international terrorism or activities in preparation therefore. 
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( TS//S I //NF ) The purpose of the BR and PRATT Bulk Metadata Programs is to support 
the Counterterrorism mission. 

( TS//S I //NF ) Bulk metadata consists of "unselected" communications events, and the 
BR and PR/TT Bulk Metadata programs complement NSA's traditional selection-based 
intelligence collection. 



( T5//5 I //NF ) (OGC Attorney): The BR and PR/TT programs are supported by two special authorities granted by the FISC which permit NSA to obtain 
telephony and internet communications bulk metadata from U.S. -based telecommunications service providers. The authority was granted by the FISC in 
support of the Counterterrorism mission to permit NSA to I earn more about a terrorist target's communications, even those terrorists potentially 
located in the United States. 



( TS//S I //NF ) Bulk metadata consists of "unselected" communications events, and the BR and PR/TT Bulk Metadata Programs complement NSA's 
traditional selection-based intelligence collection. 

( TS//S I //NF ) As you can probably imagine, bulk internet and telephony metadata, acquired within the United States, contains information to, from, or about 
U.S. persons. Therefore, because there is unminimized U.S. person information included within this type of metadata, there are special rules and 
procedures we must follow when acquiring, processing, accessing, storing, sharing, and disseminating this information. This metadata is highly sensitive 
which is why we have this specialized training. 

( TS//S I //NF ) In this course we discuss the metadata we collect, how we collect it what we are permitted to do with it as well as other special rules and 
procedures we must follow. 
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( TS//S I //NF ) (OGC Attorney): To get started, lefs discuss the individual Bulk Metadata Programs. The BR Program pertains to the acquisition of telephony 
metadata. The associated FISC Order allows NSA to ask specific U.S. -based telecommunications service providers for their business records. The 
business records, also known as call detail records, contain information about phone calls. 



(T5//SI//NF 



ram and associated FISC Order permits the collection of bulk Internet communications metadata. 




( TS//S I //NF ) Under both these FISC orders, NSA is pr ohibited from acquiring com munications content. Under these Progra ms, NSA may not listen to 
phone calls, or collect the body or subject of an email IB The Bulk Metadata authorities permit theBJ 
about the communications. ^^^^^^^^^^^^^^^^B 



( TS//S I //NF ) In Module 2, we will explore how each type of metadata is obtained and what specific information each order permits NSA to collect. 
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( TS//S I //NF ) (OGC Attorney): Due to the sensitivity of the data and the desire to protect the privacy of U.S. persons, the FISC imposes restrictions on how 
we can touch the data. For the purposes of this course, by 'touch" we mean any activity where there is an opportunity to commit a violation with regards to 
the Orders governing these authorities. We recognize that it takes a very diverse team of individuals working to see that the data is properly acquired, 
routed, prepared, stored, then queried, shared and disseminated. From acquisition to dissemination, including management and compliance, if you play a 
role in enabling this data to be used for its intelligence value, we consider you to be someone who "touches" this data. 

( TS//5 I //NF ) NSA's goal is to provide reasonable assurance that we are complying with the law AND making the most of these authorities to support the 
counterberrorism mission and protect the United States. 
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( TS//S I //NF ) (OGC Attorney): BR and PR/TT are two separate orders issued by the FISC, though the general access, sharing, dissemination, and retention 
rules are the same for the two programs. Those similarities are why the training for both is covered in t his course. Additionally, both Orders target the same 
aroups. referred to in the Orders as the Foreign Powers. The Foreign Pow ers named in the orders are I 

| Both the BR and PR/TT prog 

Articulable Suspicion, or RAS, to gain approval to query the bulk metadata with an identifier. We will get into much more detail about these two topics in 
later modules. 
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( T5//5 I //NF ) (OGC Attorney): There are two high level differences between the Orders as well. Details of the differences will be addresse d in later modules, 
but at a basic level, the biggest difference between the two Programs is how the metadata is obtained. 




( TS//S I //NF ) The other point where the Bulk Metadata Programs differ is in the area of hop restrictions for contact chaining. This will be described in detail 
in Module 4, but for now it is important to know that according to the Orders the hop restrictions are different for the BR and PR/TT Programs. 
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( TS//S I //NF ) (OGC Attorney): NSA must reapply to the FISC every 90 days to continue operating under these authorities. This process allows for the 
Government to seek modifications and for the F ISC to update these authorities to reflect changes that may affect NSA's collection and handling of BR and 
PR/TT bulk metadata. It is also crucial that all factors associated with NSA's implementation of these programs are fully compliant with the FISC Orders 
and guidelines. 

( TS//S I //NF ) As new orders are issued, this training may be augmented to address significant changes. Your organization will notify you if or when 
additional training is necessary. Should you have questions, you are strongly encouraged to contact your manager, Counterterrorism (CT) Homeland 
Security Analysis Center (HSAC), Technology Directorate (TD) Compliance, SID Oversight and Compliance, or the Office of General Counsel (OGC) for 
assistance and guidance. 
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( T5//5 I //NF ) NSA may perform SIGINT functions under various FISA authorities to include: 

• NSA FISA 

• FBI FISA 

• FAA Section 702 

• FAA Section 704 

• FAA Section 705(b) 

( TS//S I //NF ) BR and PR/TT Bulk Metadata Programs provide analysts with another opportunity to gain unique 
collection on a target 

( TS//S I //NF ) By leveraging various collection authorities, analysts can fill existing knowledge gaps on their 
target 



( TS//S I //NF ) (OGC Attorney): Now that you have a better understanding of what the BR and PR/TT Bulk Metadata Programs are, you may be wondering 
where these programs fit in the context of the broader set of SIGINT authorities. 

( TS//S I //NF ) Recall from OVSC1100, the Overview of Signals Intelligence Authorities, that we learned that in addition to E.O. 12333, NSA may perform 
SIGINT functions under various FISA authorities to include NSA FISA, FBI FISA, FISA Amendments Act (FAA) Section 702, 704, and 705(b). While there 
are specific rules governing when and how these authorities may be applied, each of these authorities has the potential to provide a valuable and unique 
complement to our E.O. 12333 collection resources. Similarly, the BR and PR/TT Bulk Metadata Programs provide analysts with another opportunity to 
gain unique collection on a target By leveraging as many of these various collection authorities available to them as permitted, analysts can fill existing 
knowledge gaps on their target. 



( TS//S I //NF ) One prime example of how an analyst leveraged several of these collection authorities to close crucial knowledge gaps on a target occurred in 
Fall 2009, when a CT analyst pieced together information obtained from E.O. 12333, FAA 702, and BR FISA authorities to reveal a terrorist plot on the New 
York subway system, which was subsequentiy disrupted by the FBI. 
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( TS//S I //NF ) Similarities beh/ueen SPCMA and BR & PRATT 

• (TS//5 l //Nr) Both involve exclusively metadata 

• (TS//S I //NI~) Both allow for querying of U.S. person identifiers under specific circumstances 



(TS//SI//NF ) Differences betvueen SPCMA and BR & PRATT 



(TS//S I //NF) Source of the metadata 

0 SPCMA procedures apply to metadata 

already lawfully collected under E.O. 

12333, NSA FISA, FBI FISA, FAA 702, 704, 

and 705(b) authorities 
0 BR and PR/TT programs authorize the 

acquisition of unselected, bulk metadata 



(TS//S I //N0 To query the 
metadata: 

0 SPCMA requires valid and 

documented foreign intelligence 

purpose 
O BR and PR/TT require RAS- 

approved identifier for a limited 

target set 



(TS//S I //NF) (OGC Attorney): It is also important to understand what the BR and PR/TT Bulk Metadata programs are not You may have heard of SPCMA - 
the Supplemental Procedures Governing Communications Metadata Analysis. They allow NSA to treat communications metadata differently than content in 
the course of the analysis of communications metadata already lawfully collected under E.O. 12333, NSA FISA, FBI FISA, FAA 70 2, 704, and 705(b) 
authorities. Specifically, given a valid and documented foreign intelligence purpose, these new procedures permit contact chaining, | 

^communications metadata identifier, irrespective of nationality or location, in order to follow or discover valid foreign intelligence 
targets. WhatSPCMA and the BR and PR/TT programs have in common, then, is that they both exclusively involve metadata, and allow for queries of 
identifiers belonging to U.S. persons. 



(TS//S I //NF) Unlike SPCMA, however, the BR and PR/TT Programs authorize the acquisition of unselected, bulk metadata. Because of the sensitivity of 
this metadata, it may only be queried with identifiers for which RAS exists to believe that the identifier is directly associated with the Foreign Powers 
specified in the Court Order granted by the FISC. You will learn much more about the RAS standard in Module 3. 
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(U) Knowledge Check 

1. ( TS//S I //NF ) What is the purpose of the BR and PR/TT Bulk Metadata Programs? 

a) (T5//S I //NF) To permit NSA to I earn more about a terrorist targets communications, even 
those terrorists potentially located in the United States 

b) ( TS//S I //NF ) To give NSA the authority to collect and analyze the content of foreign and domestic 
terrorist telecommunications traffic 

c) ( T5//S I //NF ) To enable NSA to more effectivel y collect and analyze telep hony and internet 
communications metadata associated with the| 

d) (U) All of the above 



2. (TS//S I //NF) The BR and PR/TT Bulk Metadata Programs enable NSA to query identifiers related to. 

a) All terrorists regardless of their affiliation and origin. ^^^^^^^^^^^ 

b) Terrorists/terrorist groups associated with| | Foreign Powers, I 

c) Any foreign intelligence target. ^^^^^^^^^^^^^^^ 

d) Terrorists/terrorist groups associated withB 



(U) (OGC Attorney): Let's make a few notes in our travel journal and check to see what you remember from this topic! 



ANSWERS: 

Question 1: ( TS//S I //NF ) Correct! The purpose of the BR and PR/TT Bulk Metadata Programs is to permit NSA to learn more about a terrorist target's 
communications, even those terrorists potentially located in the United States. 

( TS//S I //NF ) Incorrect. The correct answer is a). The purpose of the BR and PR/TT Bulk Metadata Programs is to permit NSA to learn more about a 
terrorist target's communications, even those terrorists potentially located in the United States. 

Quest ion 2 : ( TS//S I //NF ) Correct! The BR and PR/TT Bulk Metadata Programs enable NSA to query identifiers related to terrorists/terrorist groups who fall 
under B^Foreign PowersBJ 

(TS//G I //Nr) -Incorrect The correct answer is b). The BR and P R/TT Bulk Metadata Programs enable NSA to query identifiers related to terrorists/terrorist 
groups who fall under BB Foreign Powers| 
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(U) Knowledge Check 

3. ( T5//5 I //NF ) One of the differences between BR and PR/TT is that the 

records delivered by the telecommunications providers, while the 

live, streaming Internet communications. 

a) bulk metadata, PR/TT metadata 

b) PR/TT metadata, bulk metadata 

c) PR/TT metadata, BR metadata 

d) BR metadata, PR/TT metadata 



4. ( T5//S I //NF ) Which of the following is true of BR and PR/TT and not other authorities? 

a) ( TS//S I //NF ) In the BR and PR/TT authorities, NSA is authorized to obtain metadata in bulk from 
U.S. -based telecommunications service providers that may not be available from other collection 
sources, and NSA can only query that metadata for counter proliferation purposes. 

b) ( TS//S I //NF ) In the BR and PR/TT authorities, NSA is authorized to obtain content from U.S.- 
based telecommunications service providers that may not be available from other collection 
sources, and NSA can only query that content for counterberrorism purposes. 

c) ( TS//S I//NF ) In the BR and PR/TT authorities, NSA is authorized to obtain metadata in bulk 
from U.S. -based telecommunications service providers that may not be available from 
other collection sources, and NSA can only query that metadata for counterterrorism 
purposes. 

d) ( TS//S I //NF ) In the BR and PR/TT authorities, NSA is authorized to obtain metadata in bulk from 
foreign telecommunications service providers that may not be available from other collection 
sources, and NSA can query that intelligence for any foreign intelligence purpose. 



(No audio or transcript on this page) 



ANSWERS 
Question 3: 




(TS//S I //Nr) Incorrect. The correct answer is d). One of the differences between BR and PR/TT is that 



Question 4: (T-5 7/S I //NF ) Correct! In the BR and PR/TT authorities, NSA is authorized to obtain metadata in bulk from U.S.-based telecommunications 
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service providers that may not be available from other collection sources, and NSA can only query that metadata for counterterrorism purposes. 
( TS//5 I //NF ) Incorrect. The correct answer is c). In the BR and PR/TT authorities, NSA is authorized to obtain metadata in bulk from U.S. -based 
telecommunications service providers that may not be available from other collection sources, and NSA can only query that metadata for 
counterterrorism purposes. 
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(U //FOUO ) Now that we have completed this module, you should be able to: 

• ( TS//S I //NF ) Identify the purpose of the BR and PRATT Bulk Metadata Programs 

• ( TS//S I //NF ) Identify the ^H Fore '9 n Powers covered by the BR and PRATT Foreign 
Intelligence Surveillance Court (FISC) Orders 

• ( TS//S I //NF ) Contrast the differences in the authorities granted between BR FISC 
Orders and PRATT FISC Orders 

• ( TS//S I //NF ) Recognize the role of the Bulk Metadata Programs in the context of the 
broader set of SIGINT authorities 
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(U //FOUO ) (OGC Attorney): Now that we have completed the first part of our road trip, you should be able to: 

• ( TS//S I //NF ) Identify the purp ose of the BR and PR/TT Bulk Metadata Programs 

• ( TS//S I //NF ) Identify the^^Foreign Powers covered by the BR and PR/TT Foreign Intelligence Surveillance Court (FISC) Orders 

• ( T5//S I //NF ) Contrast the differences in the authorities granted between BR FISC Orders and PR/TT FISC Orders 

• ( TS//S I //NF ) Recognize the role of the Bulk Metadata Programs in the context of the broader set of SIGINT authorities 
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(U) MODULE 2 

(TG//S I //ND BR and PR/TT Metadata 

(U) This module will enable you to: 

• ( TS//S I //NF ) Distinguish differences between BR and PR/TT metadata 

• (TG//G I //Nr) Recognize restrictions placed on BR and PR/TT metadata storage and retention by the 
BR and PR/TT Bulk Metadata Programs 



GRAPHIC/AV: 

(U) Present learning objectives in the travel 
journal 



(TG//G I //NH ) (OGC Attorney): During this part of our trip we discuss the BR and PR/TT metadata in greater detail. Specifically, we look at the metadata 
which may be obtained, how bulk metadata is collected under these authorities, and the storage restrictions with which NSA must comply. Other modules 
will address restrictions related to the dissemination and processing of the bulk metadata. 



(U) This module will enable you to: 

• (TG//G I //NT) Distinguish differences between BR and PR/TT metadata 

• (JS//5I//NP) Recognize restrictions placed on BR and PR/TT metadata storage and retention by the BR and PR/TT Bulk Metadata Programs 



(T5//G I //MF ) Note that other restrictions will be addressed in other modules. 
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(TS//SI//NF) These Business Records 
Include Examples Such As: 

• Originating and terminating telephone 
numbers 

• IMSI 

• IMEI 

• Trunk identifiers 

• Telephone calling card numbers 



(TG//5 I //Nr ) (OGC Attorney): Lets take a look at the BR Bulk Metadata Program. As we mentioned in Module 1, the BR Primary Order pertains specifically 
to telephony metadata which is kept by U.S. -based telecommunications companies as part of their normal business operations. They retain this 
information, in part, so they can send their subscribers a bill every month. 

(T5//S I //Nr) The business records include, for example, originating and terminating telephone numbers. International Mobile Subscriber Identity (IMSI), 
International Mobile Station Equipment Identity (IMEI), trunk identifiers, and telephone calling card numbers. 
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(TS//S I //NF) These Business 
Records Do Not Include: 

• Content of any communication 

• Name, address, or financial 
information of a subscriber or 
customer 



(TG//G I //Nr) (OGC Attorney): As you can imagine, NSA is interested in the same kinds of telephony information fori 
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(T5//5 I //NT ) (OGC Attorney): In the case of Internet communications, there are no easily accessible comparable business reco rds that could provide NSA 

with the kind of information in which we are interested. Subscrib ers do not receive a bill based on who thev email^^^^^^B I I rto acquire the b ulk 

metadata for internet communications, the FISC permits NSA to| 
PR/TT metadata and forward it back to NSA for analysis. 




rrS7/G I // ME4 As we discussed in Module 1, NSA is not permitted to collect communications content under either of these Orders, so 
|in such a way as to exclude content 1 



TOP 5CCRCT//5 l //NOrOriN 
Page 5 of 32 



TOP SECRET//S I //NOroriN 



DATE/PREPARER: TAP 



Topic 

- (T5//5 I //NF -) PR/TT Bulk 
Metadata Program (cont) 



Home 



Page Classification 

5ECRET//COM I NT//NOrORN 



Exit 



Glossary 



Screen Number 
6 of 11 



Back 



Next 



FRAME ID: 2060 



NEXT FRAME ID: 2070 



BACK FRAME ID: 2050 



ALT TAG: 



GRAPHIC/AV: 



(TS//S I //NO For example, FISC requirements that affect P Ry 

• Which U.S. -based telecommunications 

• The specific 

• The types of] 

• Which specif 



include: 




(TG//G I //Nr) (OGC Attorney): The FISC goes into great detail in the Orders about many aspects of the collection to provide reasonable assurance that NSA 
is not overreaching its authority. 

(T5//S I //Nr) For example, FISC requirements t hat affect PR/ 

• Which U.S .- based telecommunications! 

• The specific! 

• The types ofl 

• Which specific! 
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(TG//G I //NT) (OGC Attorney): Both Orders mandate that the BR and PR/TT bulk metadata must be stored in repositories within secure networks under 
NSA's control. The methods for storing the results of approved queries of the bulk metadata w ill be explained in Module 4. BR and PR/TT bulk metadata 
may only be stored in authorized and specifically designated repositories. 



(TS//S I //NF) The FISC also requires NSA to mark and tag the BR and PR/TT metadata so that software and other control mechanisms may provide 
reasonable assurance that the information is only accessed by authorized personnel who have completed the required training and have the necessary 
credentials. 



(T5//5 I //NF) The bulk BR and PR/TT metadata coming into the repositories has an expiration date set by the FISC. NSA does not have the authority to 
maintain the unselected BR and PR/TT metadata indefinitely. The FISC permits NSA to maintain this metadata for 60 months from the date of collection at 
which time it must be destroyed. 
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1. (T5//5 I //Nr) Which of the following describe the BR Bulk Metadata Program: 

a) ( T5//5 I //Pvir) The BR Order pertains to telephony metadata which is kept by U.S. -based 
telecommunication companies. 

b) (T5//5 I //Nr) BR refers to Business Records which is information U.S. -based telecommunications 
companies already have in their possession and use as part of their normal business. 

c) (TD//G I //NO NSA uses Business Recordinformatior^uch as terminating telephone numbers, 
IMSI, IMEI and trunk identifiers forB Hcontact chaining analysis. 

d) (U) All of the above. 

2. (T5//5 I //Nr ) Which of the following does not describe the PR/TT Bulk Metadata Program? 

a) (TS//SI//NF) 

b) (TS//SI//NF) NSA only collects limited metadata from the communications of approved 
targets. 

c) ( TS//S I //NP NSA collects specific categories of metadata to include the 'to," 'from," "cc," and 
"bcc" lines of an email. 

d) (U) None of the above. 

4 Which of the following statements is true? 

a) ( T5//5 I //NF ) Bulk BR and PR/TT metadata may not be kept for longer than 48 months. 

b) (T5//5 I //NF) Non-U. S. person metadata may be kept at NSA indefinitely. 

c) (TG//S I //Nr) The bulk metadata is tagged to provide reasonable assurance that the data is 
only accessed by authorized personnel. 

d) (U) All of the above. 

e) (U) None of the above. 



(U) (OGC Attorney): Let's check what you remember from this topic! 



ANSWERS: 

Question 1. ( TS//S I //Nr) Correct! All of the above describe the BR Bulk Metadata Program. 

(TS//SI//NF) Incorrect The correct answer is d). All of the above describe the BR Bulk Metadata Program. 



Question 2. (TS//5 I //I 
of approved targets. | 




from the communications 
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TTG//5 1 //NT )- Incorrect The correct answer is b) because it is NOTTRUE that for the PR/TT Bulk Metadata Program NSA only collects limited metadata 
from the communications of approved targets. 



Question 3. (TS//S I //NF ) Right! The bulk metadata is tagged to provide reasonable assurance that the data is only accessed by authorized personnel. 
(TG//G I //NO Incorrect. The correct answer is c). The bulk metadata is tagged to provide reasonable assurance that the data is only accessed by authorized 
personnel. 
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(U) Now that we have completed this part of your trip, you should be able to: 

• - (TS//3 I //NO Distinguish differences between BR and PRATT Bulk Metadata 

Programs 

• - (T S //S I //Nr -) Recognize restrictions placed on metadata storage and 
retention by the BR and PRATT Bulk Metadata Programs 



(U) (OGC Attorney): Now that we have completed this part of our trip, you should be able to: 

• (TS//G I //NO Distinguish differences between BR and PR/TT Bulk Metadata Programs 

• (TS//S I //NF) Recognize restrictions placed on metadata storage and retention by the BR and PR/TT Bulk Metadata Programs 



(TS//S I //NF) During the next portion of our trip, we will meet up with Marvin who will talk to us about the Reasonable Articulable Suspicion (RAS) standard 
and the requirements that must be met in order to query the bulk metadata. 
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(U) Module 3 

(U) Establishing Reasonable Articulable Suspicion (RAS) 

(U) This module will enable you to: 

• (TS//S I //Nr) Recognize the direct relationship between the Foreign Powers and 
establishing RAS 

• (T5//S I //NF) Identify the key components of RAS and how it is applied to candidate 
identifiers 

• (TS//S I //N F ) Identify who can adjudicate and approve a RAS nomination 

• (T5//5 I //Nr) Recognize the requirement associated with identifiers linked to U.S. 
persons - the OGC First Amendment Review 

• (TS//S I //MF ) List common sources of information used to construct a RAS 
nomination statement 



(TS//5 I //NF) (OGC Attorney): This part of our trip will provide you with an overview of the Reasonable Articulable Suspicion (RAS) Standard including 
definitions and descriptions to help you understand how to satisfy RAS and how to apply it to identifiers under the BR and PR/TT FISC Orders. In addition 
to this training, guidance is also outlined in a RAS memo that can be obtained from the Office of General Counsel. 

(T5//SI//NF) This module will enable you to: 

• tTS//SI//NT> Recognize the direct relationship between the Foreign Powers and establishing RAS 

• (TG//G I //Nr) Identify the key components of RAS and how it is applied to candidate identifiers 
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• (T5//G I //NO Identify who can adjudicate and approve a RAS nomination 

• (TG//S I //NO Recognize the requirement associated with identifiers linked to U.S. persons - the OGC First Amendment Review 

• (TS//5I//NF) List common sources of information used to construct a RAS nomination statement 

(TG//G I //NO At the conclusion of this module you should understand that an identifier must be RAS-approved before conducting a query. The topic of 
querying BR and PR/TT bulk metadata will be discussed in Module 4. 
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4TG//SI//NP) Who can be targeted under the BR and PRATT authorities? 




(TS//S I //NF) ThePjjForeign Powers named in these authorities a 



<TS//G I //Nr ) NSA is not permitted to query the BR and PRATT metadata unless there is a 
reasonable articulable suspicion that the identifier is associated with one of the F ISC- 
approved groups. 



tT5//G I //Nr- ) (OGC Attomev)^rheBRandPR^^^rderslisUDvn authority. T_ 

Foreign Powers areBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB The Orders detail \ 

NSA is not permitted to query the BR and PR/TT metadata unless there 
is a reasonable articulable suspicion that the identifier is associated with one of the F ISC-approved groups. 



(TG//G I //NO It is important to note that you cannot query using just a ny foreign intelligence target Furthermore, vou cannot query using just any terrorist 
JargetJrto^CAN however query using identifiers specifically linked to| 

las named in the Orders. Note that the lists may evolve and your target may be added or removed overtime, so you should reference the 
most current version of the lists for updates. 



TOP SECRET//G I //NOrORN 
Page 3 of 17 



TOP SECRET//S I //NOFORN 



DATE/PRE PAR ER: 11/09/2010 SLS 



Topic 

(U) What is RAS? 



Home 



Page Classification 

TOP 5ECRET//COM I NT//NGTORN 



Exit 



Glossary 



Screen Number 
3 of 13 



Back 



Next 



FRAME ID: 3030 



(U) What is Reasonable Articulable Suspicion (RAS)? 



NEXT FRAME ID: 3035 



BACK FRAME ID: 3020 



(U) Reasonable Articulable Suspicion (RAS) Standard 

(TS//S I //Nr> An identifier will meet the Reasonable A rticul able Suspicion Standard if based on 

the factual and practi cal consi derati ons of everyday I i f e on whi ch reasonabl e and prudent 
persons act, there are facts gi vi ng ri se to a reasonabl e arti cul abl e suspi ci on that the i denti f i er i s 
associated with one of the specified Foreign Powers. 

- Forei gn I ntel I i gence Survei 1 1 ance Court 



ALT TAG: 



GRAPHIC/AV: 

(U) Display pop-up with the definition of 
RAS as it is discussed. 



(TS//SI//NF) (OGC Attorney): The FISC recognizes the potential counterterrorism advantage gained through analysis of the BR and PR/TT bulk metadata; 
however, because there is a great deal of U.S. person information included in the bulk metadata, the FISC has set strict guidelines on when and how 
analysts can access the metadata under these authorities. The RAS standard is one of these guidelines which helps to provide reasonable assurance that 
only legitimate terrorism-related identifiers are used to query the bulk metadata. This standard must be met before queries can be conducted. 



(TS//S I //NF ) So what is RAS? RAS is a legal standard that describes the measure of proof required to support a decision whether to permit an identifier to 
be queried from the bulk metadata. The Reasonable Articulable Suspicion standard requires justthat-a suspicion that you can explain in a reasonable way. 
It does not require certainty, but is more concrete than a simple hunch. It may be easiest to think of it in terms of other standards with which you may be 
familiar. 



( I S//IJI//NI-) Many of you may be familiar with legal standards of proof applicable in other situations. It may be helpful to understand how the RAS standard 
compares to these other legal standards. For example, a jury in a criminal case will not convict an accused unless the evidence of guilt is "beyond a 
reasonable doubt. 'This is the highest legal standard of proof. A jury in a civil case (such as a personal injury case or a contract dispute) might award a 
plaintiff money damages if the plaintiff proves the elements of his claim by "a preponderance of the evidence. "This standard is lower than "beyond a 
reasonable doubt." Lower still is the standard of proof required to justify issuance of a search warrant - "probable cause" - whether that search warrant is 
for the suspect's home or the content of the suspect's communications. The RAS standard falls below "probable cause." 
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(T5//5 I //NF) The FISC has determined that this lower standard of proof is reasonable for the querying of metadata because communications metadata 
does not carry with it the same privacy protections as communications content The RAS standard falls below "probable cause" but above a mere hunch or 
guess. 
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(TS//G I //NT) An identifier will meet the Reasonable A rticul able Suspicion Standard if based on 

the factual and practi cal consi derati ons of everyday I i f e on whi ch reasonabl e and prudent 
persons act, there are facts giving rise to a reasonable articulable suspicion that the identifier is 
associated with one of the specified Foreign Powers." 
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GRAPHIC/AV: 
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RAS Equation 

Identifier + Link to Foreign Power = RAS 



(TS//SI//NF) (OGC Attorney): As it applies to the BR and PR/TT Orders, RAS is a suspicion that an identifiet^ucl^sanemai^ddressjele^ 
or other identifier type, is associated with one of the^H Foreign Powers named in BR and PR/TT Orders | (The 
F ISC requires that NSA base that suspicion on a certain level of factual evidence — and NSA must articulate those facts that connect the identifier with one 
of the named terrorist organizations. The requirement that these facts be articulable effectively provides reasonable assurance that analyst queries of the 
metadata are based on substantive information (meaning more than simple hunches or uninformed guesswork). So in order to obtain RAS approval for an 
identifier, analysts must provide enough factual evidence that it would lead a reasonable person to suspect that an identifier is associated with one of the 
named Foreign Powers in the BR and PR/TT Orders. We will get more into the kinds of facts that may be used and how they can support a RAS 
nomination later in this module. 



(T5//5I//Nr) In summary, based on the factual and practical considerations of everyday life 
determine if there is a reasonable articulable suspicion that the identifier is associated with [ 

(named in the Orders. There must be at least one qualifying fact giving rise to the suspicion that the identifier is associated 
with one of the Foreign Powers listed in the BR and PR/TT Orders. Unless that determination is made, the identifier cannot be approved to query this 
metadata repository. NSA's implementation of the BR and PR^TOrders mandates that the RAS nomination statement must clearly link the identifier/target 
to one of the Foreign Powers and documenl II u In n In n i n i^^^^^^B mil in 1 1 will be discussed later in the module. 
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(T5//SI//NF) (HMC Character): From an Anah 
BR and PR/TT and other SIGINT authorities, 
considered less than that required for FBI CT 


/sis and Production standpoint, lefs look at RAS in the context of the analyst level of effort required to utilize 
As the illustration shows, the level of effort required by an analyst to establish RAS would normally be 
FISA or FAA 704/705b, but it is more than what is needed to utilize E.O. 12333, for example. 
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(U) Who can make a RAS determination? 

(U// FOUO) Homeland Mission Coordinators (HMCs) 

(U/ /rOUO ) Chief of the CT Homeland Security A neJysis Center 

(U/ /FOUO) Deputy Chief of the CT Homeland Security Analysis 
Center 

(U) No one else can make this determination! 



TTG//5I//NF-) (OGC Attorney): The FISC states that the RAS decision is based on considerations of "reasonable and prudent persons." This does not, 
however, mean that anyone can approve an identifier for RAS. There are a select number of people within NSA who have been given the authority to 
approve identifiers for querying under these two authorities. Those individuals are called Homeland Mission Coordinators or HMCs. 

( TG//5 I //Nr) (HMC Character): As was just mentioned, RAS determinations are typically made by specially trained personnel in the Office of 
Counterterrorism and its Extended Enterprise; these individuals are titled Homeland Mission Coordinators, typically abbreviated as HMCs. These 
individuals, like me, have been given special training on how to apply the RAS standard and how to apply it consistently. HMCs are specially trained 
individuals who have extensive experience working with this target set and who have extensive experience working with these authorities. The HMCs can 
take a RAS nomination, review the facts, and make a determination as to whether or not that particular identifier meets the RAS standard. 



(TS//S I //NT) (HMC Character): According to the BR and PR/TT Orders, in addition to the HMCs, the Chief and Deputy Chief of the Counterterrorism 
Homeland Security Analysis Center are authorized to make a RAS determination; although, it is generally the HMCs who make the RAS determinations. To 
reemphasize, no one else is authorized to make RAS determinations according to the Orders. 
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(TS//SI//NF) (HMC Character): There are certain identifiers that require an extra RAS review/approval step. As you might imagine, those are the identifiers 
that are reasonably believed to be used by U.S. persons. Why does this matter? It matters because the U.S. Government is forbidden from regarding a 
U.S. person as associated with a Foreign Power solely because he or she is exercising his or her First Amendment rights. 



(TG//G I //Nr) ( OGC Attorney): That's right. Any identifier believed to be used by a U.S. person must be forwarded to the OGC by a Homeland Mission 
Coordinator following his or her approval. An OGC attorney will review the RAS nomination, as well as the RAS decision made by the Homeland Mission 
Coordinator, and make a determination as to whether or not NSA is targeting that individual based solely on activities that are protected by the First 
Amendment to the Constitution. If there is any indication that the RAS is based solely on information or evidence protected somehow by the F irst 
Amendment, OGC will require additional information to support the RAS nomination. 

(TS//G I //NT ) (HMC Character): If you are an analyst should you abandon a RAS nomination if there is a potential First Amendment concern? Absolutely 
not. The presence of First Amendment evidence does not invalidate a RAS, it just cannot be the sole basis for a nomination. The OGC review is really 
transparent to the analyst, though it is a part of the process that you should be aware of. 



TOP SECRET//S I //NOrORN 
Page 9 of 17 



TOP SECRET//S I //NOFORN 



DATE/PRE PAR ER: 11/09/2010 SLS 



Topic 

(U) Sources of I nformation 
Used to J usitfy RA5 



Home 



Page Classification 

TOP SECRET//COM I NT//NOFORN 



Exit 



Glossary 



Screen Number 
8 of 13 



Back 



Next 



FRAME ID: 3070 



(U) What sources of information can be used to justify RAS? 



NEXT FRAME ID: 3080 



BACK FRAME ID: 3060 



ALT TAG: 



GRAPHIC/AV: 



(T!y/a//Nr) Fl SA Orders 



Existi ng Fl SA Orders 



TT575I77NF* Reports and/or RAW 
SIGINT 

SIGINT reports 

F I SA survei 1 1 ance data deri ved from other 
authori zed targets 

Raw SI Gl NT (after a Reporti ng Source 
Validation Check) 
SIGDEV Work 
Other transcri pts 



(TG//5I//ND IC and Public Sector 

Federal Bureau of I nvestigation documents 
Central I ntel I i gence Agency documents 
National Counterterrorism Center 
documents 

Documents from other U.S. Government 

Organizations 

Foreign Partner nations 

Public records available on the 
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( I b//bl//Nh) (HMC Character): So now let's look at the type of evidence that can be used to justify RAS. NSA can use any information that is lawfully in our 
possession. A published SIGINT report describing the results of electronic surveillance of a target might be more reliable than say pocket litter found during 
a detainee's interrogation — but NSA can rely on any lawfully held evidence. The HMCs are responsible for assessing the quality and reliability of the 
evidence. 



(T5//5 I //Nr ) (OGC Attorney): Sources that are often used to justify a RAS nomination include, but are not limited to: 
Existing FISA Orders 
• SIGINT reports 

FISA surveillance data derived from other authorized targets 

SIGINT traffic, as long as the submitting analyst has performed a Reporting Source Validation Check 
SIGDEV work (with verified sources), and 
Other transcripts 




If an analyst/requestor uses unpublished query results in a RAS justific ation, and the y classify the material appropriately as 
then that information will only be visible to thoseB Husers with B HorB H credentials, as confirmed 
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(TS//SI//NF) (OGC Attorney): The following IC and public sector (open source) sources are also examples of sources that are frequently used: 
Federal Bureau of Investigation (FBI) documents 
Central Intelligence Agency (CIA) documents 
The National Counterterrorism Center (NCTC) documents 
Documents from other U.S. Government Organizations 
Foreign Partner nations, and 

Public records available on the internet, newspapers, or other public resources. 
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• (TG//G I //NT) Supports the Homeland Defense Counterterrorism (CT) Mission. 

• (TS//S I //NF ) Provides the ability to request, justify, review, approve/disapprove RAS 
nomi natio ns/requests . 

• (TS//G I //NT) Is the authoritative source for the list of RAS-approved identifiers and will export that list to 
other systems that require it 

• (TS//S I //NF ) Provides metrics and other information to facilitate oversight review and report generation for 
the Department of J ustice (DOJ ) and the FISC. 

(U) Time Bounded Approvals 



(T5//5 I //NO (HMC Character): Remember from earlier in this module, we introduced the RAS process as a simple equation: identifier + link to Foreign 
Powers =RAS. Now you may be wondering how an identifier is nominated for RAS. NSA must demonstrate and document that e\^^^^^r used to 
query the bulk metadata meets the RAS standard PRIOR to querying the BR and PR/TT bulk metadata repositories. NSA created| | the RAS 

identifier management tool, to streamline the adjudication of the RAS nomination statements and documentation of RAS determinations. 



(TG//G I //Nr ) (HMC Character): Typically, an intelligenceanal^t will gather the necessary information and draft the nomination statement in IRONMAN 
articulating the RAS equation. An HMC, also usinaB I will review the nomination statement and approve or disapprove the request. If the 

nomination statement is for a U.S. person, the( (tool includes functionality that allows the HMCs to forward such requests to OGC for the required 

First Amendment review. In either case, if the RAS nomination is approved, the identifier is now authorized for querying. 



(T5//5 I //N F) (OGC Attorney): Through 
IRONMAN provides the ability to 
of RAS-approved identifiers, and 





NSA documents all RAS-approved identifiers, 
tify, review, approve/disapprove RAS nominations 
exports that list to other systems that require it. 




the rationale used to gain RAS approval. 

is therefore the authoritative source for the list 



(TS//S I //N F) (OGC Attorney): It is important to remember that copies of the documents, such as court orders or reports, are required as part of the 
nomination process. The paper trail should enable an auditor from Department of J ustice (DOJ ) to clearly evaluate all of the evidence presented to support 
a RAS decision. 
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(TG//G I //NO (OGC Attorney): NSA has overseers, specifically the DOJ National Security Division attorneys, who examine the factual support for our R AS 
decision process. They take a look at any notes that the HMCs or someone within the NSA OGC may have included, and they decide whether or not we 
have properly applied the R AS standard to all of the identifiers that are used to query the bulk metadata. So it is critical that we take great carethrouahout 
the process, gathering and presenting the evidence and applying the RAS standard in a consistent manner across all identifier nominations. I 
also provides metrics and other information to facilitate this oversight review and report generation for the DOJ and the F ISC. 

(TS7/G I //NO (OGC Attorney) The Court recognizes that occasionally, NSA may have information suggesting that a target may have used a particular 
identifier only for a limited time. In such cases, an HMC can determine that the RAS standard is met for the specifictimeframe that the identifier was 
believed to be used by the target Such instances are considered Time Bounded and are uniquely dealt with in I I Analysts encountering targets 

under these circumstances should consult with an HMC on how to proceed. ^^^^^^^ 
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fTS//G I //Nr ) After the sunset of an identifier's RAS approval — or anytime before 
identifier can be submitted for RAS revalidation through the same process. 



the 



(TS//5 l //Nr ) (HMC Character): RAS approvals have sunset or expiration dates which analysts must comply with. Currentiy a RAS approval on a foreign 
identifier, per the FISC, is legally valid for one year. However, NSA CT has taken a conservative approach and implemented guidance that mandates RAS 
review and re-approval every 180 days. Likewise, a RAS approval for an identifier believed to be used by a U.S. person has a legal lifespan of 180 days 
per the FISC, but NSA CT has implemented guidance requiring review and re-approval every 90 days. It is the analyst's responsibility to monitor the sunset 
dates and take appropriate actions before the RAS nomination expires. 

(TS7/S I //Nr ) (HMC Character): Any identifier can be resubmitted for revalidation at any time. Revalidations require proof of the same categories of 
information that was required for the original request. Revalidations should try to validate that the original evidence is still true by presenting any new 
documentation to demonstrate that the identifier is still associated with the Foreign Powers named in the Orders. It is up to the HMCs to make an informed 
revalidation, based on the totality of the evidence. If you are uncertain of your evidence, submit the nomination anyway and work with the HMCs through 
the process. 
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(U) Knowledge Check 

1. ( T5//5 I //NT ) Why is the link between the target and the Foreign Powers an essential part of the RAS 
nomination? 

a) (TS//5 I //NF) It is a key component in reaching the 'probable cause' standard 

b) (T5//5I//NF) It is representative of the terrorist centric scope of the BR and PR/ 1 I authorities 
as noted in the FISC Orders 

c) (U) Because it is required by USSID SP0018 and DoD 5240.1-R 

d) (U) Because it is required in a DIRNSA Memo 

2. (T5//5 I //Nr ) The RAS standard requires that what two facts are articulable? 

a) (TS//SI//NF) The identifier can be tied to a terrorist target and that target can be tied to 

b) (TS//SI//NF) The identifier is not used by a U.S. person and they are engaged in terrorist 
activities 

c) fT5//5i//rtff ) The identifier can be tied to a ta rget and that target is affiliated with| 

d) (TS//SI//NF) The query can be traced back to the analyst who submitted it and the identifier is 
associated with any terrorist group. 



(U) (HMC Character): Let's check what you remember from this topic! 



ANSWERS: 

Question 1: (TS//SI//NF ) Correct! The link between the target and the Foreign Powers is an essential part of the RAS nomination because it is 
representative of the terrorist centric scope of the BR and PR/TT authorities as noted in the FISC Orders. 

(TS//SI//NF) Incorrect. The correct answer is b). The link between the target and the Foreign Powers is an essential part of the RAS nomination because it 
is representative of the terrorist centric scope of the BR and PR/TT authorities as noted in the FISC Orders. 



Question 2: (T5//5 I //Nr) Correct! The RAS standard requires that the following two facts are articulable: 

• The identifier can be tied to a terrorist target, and 

• That target can be tied to | 
(TS//SI//NF) Incorrect The correct answer is a). The RAS standard requires that the following two facts are articulable: 

• The identifier can be tied to a terrorist target, and 

• That target can be tied to ^^^^^^^^B^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^B 
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(U) Knowledge Check 

3. (T5//5I//NF) Who may make a RAS determination? 

a) (TG//G I //NT) A Homeland Mission Coordinator (HMC) or an attorney with the Department of 
J ustice 

b) (TG//GI//Nr) An HMC or other official named in the Orders 

c) (T5//5 I //NF) Any reasonable and prudent analyst (and OGC if identifier is believed to be used by 
a U.S. person) 

d) (TS//S I //NF) Only a judge from the F ISC 

4. (TS//5I//NT) Which source of information may be used to justify RAS? 

a) (TG//G I //ND SIGINT reports 

b) ( T5//G I //Nr) Open source information 

c) (TS//S I //Nr) Second Party reports 

d) (T5//5 I //N F) All of the above 

5. (TG//G I //N P ) What additional requirement is needed for an identifier reasonably believed to be used by a 
U.S. person? 

a) ( T5//5 I //Nr ) Must be reviewed by the Attorney General 

b) ( TG//G I //NT) Must be reviewed by the Chief of the Homeland Security Analysis Center 

c) (T5//5I//NF) Must be reviewed by OGC 

d) (TG//G I //Nr ) Two HMCs must agree on the RAS determination 



Question 3: ( T5//5 I //Nr ) Correct! An HMC or other official named in the Orders may make a RAS determination. 

(TG//G I //NT) Incorrect. The correct answer is b). An HMC or other official named in the Orders may make a RAS determination. 

Question 4: (TG//G I //NT ) Correct! SIGINT reports, open source information, and Second Party reports may all be used to justify RAS. 

(TS//SI//NF) Incorrect. The correct answer is d). SIGINT reports, open source information, and Second Party reports may all be used to justify RAS. 

Question 5: (TG//G I //NT ) Correct! If an identifier is reasonably believed to be used by a U.S. person, then it must be reviewed by OGC. 

(TS//S I //NF) Incorrect. The correct answer is c). If an identifier is reasonably believed to be used by a U.S. person, then it must be reviewed by OGC. 
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(U) Now that we have completed this part of your trip you should be able to: 

(TS//S I //NF) Recognize the direct relationship between the Foreign Powers and 
establishing RAS 

(TS//S I //MF) Identify the key components of RAS and how it is applied to candidate 
identifiers 

(T5//5 I //Nr) Identify who can adjudicate and approve a RAS nomination 

(TS//S I //NF) Recognize the requirement associated with identifiers linked to U.S. 
persons - the OGC First Amendment Review 

(T5//S I //Nr) List common sources of information used to construct a RAS 
nomination statement 



(TS//SI//NF) (HMC Character): So remember, RAS nominations are approved by an HMC (or an official named in the Order) BEFORE queries can be 
made using a particular identifier within the BR or PR/TT metadata. 

(U) (OGC Attorney): Now that we have completed this part of the trip you should be able to: 

(T5//5 I //NT) Recognize the direct relationship between the Foreign Powers and establishing RAS 

( TS//G I //N T) Identify the key components of RAS and how it is applied to candidate identifiers 

(TS//SI//NF) Identify who can adjudicate and approve a RAS nomination 

(TS//S I //NF) Recognize the requirement associated with identifiers linked to U.S. persons - the OGC First Amendment Review 
(TS//SI//NF) List common sources of information used to construct a RAS nomination statement 
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COURSE: ( TS//S I //NF ) OVSC1205 Special Training on FISA (Analytical) 
COURSE: ( TS//S I //NF ) OVSC1206 Special Training on FISA (Technical) 

Module 4: (TS//S I //NF ) Access, Sharing, Dissemination, and Retention Under the BR and PR/TT FISC Orders 



DATE/PREPARER: SLS 



Topic 

(U) Module 
Introduction 
Home 



Page Classification 

TOP SECRET//COMINT//NOFORN 



Exit 



Glossary 



Back 



Screen Number 
lof 27 



Next 



FRAME ID: 4010 



NEXT FRAME ID: 4020 



BACK FRAME ID: n/a 



ALT TAG: 



GRAPHIC/AV: 

(U) Image of OGC Attorney, HMC 
Character, and SV Character sitting at a 
table 



(U) Module 4 

(TS//S I //NF ) Access, Sharing, Dissemination, and Retention Under the BR and PR/TT 
FISC Orders 

(U) This module will enable you to: 

• ( TS//S I //NF ) Distinguish between the analysts authorized to query BR and PR/TT 
metadata and those authorized to view query results 

• ( TS//S I //NF) Recognize the contact chaining restrictions for RAS-approved 
identifiers 

• (TS//S I //NF) Recognize what constitutes unique BR and PR/TT query results 

• (TS//S I //NF) Identify limitations that impact the access, sharing, dissemination, and 
retention of BR and PR/TT query results 

• (TS//S I //NF) Recognize the BR and PR/TT dissemination tracking requirement and 
the additional CT nexus requirement for U.S. person identifiers 



Derived From: NSA/CSSM 1-52 
Dated: 20070108 
Decl assif y On: 20360101 
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( TS//5 I //NF ) (OGC Attorney): During this part of our trip we will identify the limitations regarding access, sharing, disseminating, and retaining of BR and 
PR/TT query results. 

(U) This module will enable you to: 

• ( TS//S I //N F) Distinguish between the analysts authorized to query BR and PR/TT metadata and those authorized to view query results 

• ( T5//5 I //NF ) Recognize the contact chaining restrictions for RAS-approved identifiers 

• ( TS//5 I //NF ) Recognize what constitutes unique BR and PR/TT query results 

• ( TS//S I //IMF ) Identify limitations that impact the access, sharing, dissemination, and retention of BR and PR/TT query results 

• ( T5//5 I //NF ) Recognize the BR and PR/TT dissemination tracking requirement and the additional CT nexus requirement for U.S. person identifiers 

( T5//5 I //NF ) If you are a technical person, you might be asking yourself if this information is directiy applicable to you and your team. Compliance with the 
FISC Orders could be jeopardized by inadvertent or unintended changes in the infrastructure maintained by technical personnel. Therefore, an 
understanding of the requirements outlined in the Orders is important in the event that any technical support functions (data access, presentation, 
underlying system support - both hardware and software, etc.) cause changes to the support infrastructure that would bring NSA's compliance with the BR 
and PR/TT Court Orders into question. 
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( T5//5 I //NF ) (SV Character): Access to BR and PR/TT raw metadata and query results is restricted to those who have the required training and appropriate 
credentials. The Office of the Director of Compliance (ODOC) through the Signals Intelligence Directorate's Office of Oversight and Compliance (SV) 
controls access to the BR and PR/TT FISA metadata, ensuring that only those who have completed all of the required training and have been granted the 
appropriate credentials are permitted to touch the metadata. 



( TS//S I //NF ) Within the analyst workforce, a distinction is made between individuals who are permittedtoauerWhedataandthose who are permitted only 
to view the query results. Individuals who are authorized to query BR and PR/TT metadata sets haveH ^credentials. Division level 

management within a production center determines when query permissions will be granted to analysts based on a mission need, not solely on completion 
of BR and PR/TT FISA Training. Some technical personnel may also require query access, but their queries are for the purposes of data accuracy and 
integrity, not for target or intelligence analysis. Managers of technical personnel who require query permissions will make the determination in concert with 
their organization's compliance office, usually either SV or TV (the Technology Directorate's office of compliance). 
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( T5//S I //NF ) (SV Character): So, how do you determine if an analyst or technical colleague has the appropriate credentials? | 



lis a tool that can 



you check someone else's credentials against your own. From your NSANet machine, type 



| Lookup Utility. Insert the sid of the analyst or technical 
share in common are displayed. From that you can determine if they hold the 
some reason, you should contact SV4 to verify the individual's credentials before proceeding 




jin your web browser. This takes you to the 
with and hit search, the formal accesses you 
redentials. If the utility is not functioning for 
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( TS//S I //NF ) The Court Orders require that when the metadata is queried for intelligence 
analysis purposes that an auditable record be generated. 

Haudit log includes: 



( TS//S I //NF ) The | 

• Query requests 

• User login 

• IP address 

• Date and time of the access 

(TS//S I //NF) What is the EAR and how does it function as a compliance safeguard? 



( T5//5 I //NF ) (SV Character): The BR and PR/TT Court Orders require that an auditable record be generated whenever metadata is queried for intelligence 



and PR/TT metadata is queried in| |an automatic audit log is generated to enable appropriate oversight of 
queries performed by both analysts and technical personnel and reviews the following on a periodic basis: 



analysis purposes. When th 
these Authorities. SV audits 

• Query requests 

• User login 

• I ntemet P rotocol (IP) address 

• Date and time of the access 

(TV/SI//NFWHMC^:haracter): While these audits are one way to verify that only RAS-approved identifiers are used as seeds to query the BR and PR/TT 
metadata, | | the analytic tool used to query this metadata, employs an Emphatic Access Restriction (EAR) software to provide reasonable 
assurance that only RAS-approved identifiers are queried by analysts. While the EAR is of great benefit for analysts, it should not lessen awareness and 
attention to detail while using the NSA tools and applications associated with BR and PR/TT. We'll discuss the EAR in greater detail later in this module. 



Comment [SLS1] : Notefor audio recording, this 
is pronounced as a wore 



Comment [SLS2] : Notefor audio recording, this 
is pronounced as a word "EAR" (not as letters) 
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BACK FRAME ID: 4030 
ALT TAG: 
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(U) Image of OGC Attorney, HMC 
Character, and SV Character sitting at a 
table 


(TS//SI//NF) Sourcing of BR and PR/TT Metadata Records 

(TS//SI//NF) Within NSA's source systems of record, BR and PR/TT metadata records 
tagged as to their origin, which allows for: 

• Determining if information is derived from the BR or PR/TT repository 

• Software and other management controls to function properly 


are 




(T5//5I//NF) (OGC Attorney): Another aspect of data access and governance is the requirement for the sourcing of BR and PR/TT metadata records. As we 
mentioned in Module 2, the metadata must carry unique markings, or tags. These tags allow the analyst to determine if a particular piece of information is 
derived from either the BR or PR/TT repository. In addition, these markings enable the EAR software and other management controls to function properly. 
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1. ( T5//5I//NF ) Identify the individuals or groups below who are authorized to receive and view results of 
queries that contain BR and/or P R^rrdate^please check all that apply). 

Individuals wiUil Icredentals ^^^^^^^^^^^^ 

HMCs with | ^ncl analysts with J 

c) Technical personnel witfiH | credentials 

d) Your office chief and oversight personnel by virtue of their positional responsibility 

e) None of the above 

2. ( TS//5 I //NF ) What should you do before sharing the results of a B^or P R/TT query with a co-worker 
working on a target reasonably believed to be associated with the^^V 

a) Read your e-mail to see if your co-worker asked you for the information 

b) Call one of the SOOs in the NSOC to find out if information about your target can be 
released to your co-worker 

c) Verify that the co-worker has the proper credentials to have access to BR and PRATT 
information 

d) All of the above 



(U) (SV Character): Lefs check in and make a few quick notes in our travel journal and see what we remember from this topic. 



ANSWERS: 

Question 1. ( TS//S I /NF ) Correct! a), b), and c) describe individuals and groups holding | B :rec 'entials. 

( TS//S I /NF ) Incorrect Positional authority does not supersede the requirementto have these specific credentials. Not all managers or SV personnel may 
require these credentials for their specific jobs. The correct answers are a), b), and c). 

Question 2. ( TS//S I /NF ) Correct! Before you share any BR or PR/TT query results with a co-worker, you must first verify that he or she has the proper 
credentials to have access to BR and PR/TT information. 

( TS//S I /NF ) Incorrect The answer is c). Before you share any BR or PR/TT query results with a co-worker, you must first verify that he or she has the 
proper credentials to have access to BR and PR/TT information. 



TOP SECRET//S I //NOFORN 
Page8of 39 



TOP SECRET//SI//NOFORN 




DATE/PREPARER: 


Topic 

(TS//5I//NF) Querying the 
BR and PR/TT Metadata 


Page Classification 

TOP 5ECRET//COMINT//NOFORN 


Screen Number 
7 of 27 








Home 


Exit 1 Glossary 


Back Next 






FRAME ID: 4060 


(TS//SI//NF) Analyst Queries of the BR and PR/TT Metadata 








(U) Have RAS, will query? How? 








NEXT FRAME ID: 4070 


(TS//SI//NF) How do 1 recognize BR and or PR/TT results, and what are "unique" results? 






(U) Once 1 have results, how do 1 handle them? Are there any restrictions? 






BACK FRAME ID: 4050 












ALT TAG: 












GRAPHIC/AV: 

(U) Display and fade out the questions 
shown as an intra to the topics to be 
covered in this section. 












(U) For the transcript paragraph spoken by 
the Technical Character, consider using a 
creative treatment that shows the character 
for a brief period and then fades her out 
(perhaps a news bulletin or a postcard??). 












(T5//5I//NF) (HMC Character): In this section of the module, we'll cover how analysts query the BR and PR/TT metadata. In addition, we'll go into detail on 
what constitutes BR and PR/TT results and how to tell if they are unique. Since BR and PR/TT unique results may only be shared with individuals who 
have the proper credentials, being able to identify unique BR and PR/TT query results will help you comply with the sharing and handling restrictions. 




(TS//SI//NF) (Technical Character): While this section may appear to be more focused on analytic-specific tools, certain technical personnel also query 
these datasets to provide reasonable assurance of data integrity or to make the metadata usable for intelligence analysis. Therefore, technical personnel 
and their managers should also be aware of guidelines related to queries, handling instructions for query results, in any form, and the requirements related 
to sharing of unique query results, in any form. 
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( TS//SI//NF ) How are Analyst Queries of the BR and PR/TT Metadata Conducted? 



(TS//SI//NF) Queries of BR and PR/TT metadata are conducted tlirough| |the user 
interface to J |As a default, queries are federated with data from other collection 

sources. 



CHCt 
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tuetedi 





? [PH FISABR Mode 
IZ] FISABR 
[PI E0 12333 



( T5//5 I //NF ) (HMC 
the user interface to| 



nee RA5 approv ed, an ide ntifier can be used to query the BR and/or P R/TT metadata via authorized versions of 
When launching | | analysts with the appropriate BR or PR/TT credentials have the option to check a box i f the' 

TRY Mode" box when logging into 



wish to in clude BR or PR/TT metadata in their queries. If an analyst checks the 'jFISABR Mode" or 'P 
| will perform a federated query. This means that in addition to either BR or PR/TT metadata, 
additional collection authorities, depending on the analysts credentials. Therefore, when performing^ 
potentially receive results from all of the above collection sources. Users of more recent versions of 
the query, and pick and choose amongst the collection sources that they would like to query. 



iwill also query data collected under 
of the BR or PR/TT metadata, analysts will 
lo have the option, however, to "unfederate" 




omment [SL53]: Notefor audio recording, this 
should be pronounced as trie word FISA trientne 
lettersB R, so simply "FISA B R" 

Comment [a4]: See Screenshot 1. 
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( TS//SI//NF ) How are Analyst Queries of the BR and PR/TT Metadata Conducted? 



NEXT FRAME ID: 4077 



BACK FRAME ID: 4070 



ALT TAG: 



GRAPHIC/AV: 

(U) Look at Annie's notes and match 
transcript to screen shots. 



( TS//S I //NF ) (HMC Character): Once you are operating within the BR or PR/TT mode of m m remember that you may only use a RAS-approved 
identifier to query the metadata. A RAS-approved identifier that is used to initiate a query of BR or PR/TT metadata is referred to as a 'seed" since it is 
being used to produce a "chain" of metadata contacts, known as contact chaining. 

( TS//5 I //NF ) | ^employs the EAR software to provide reasonable assurance that only RAS-approved identifiers are queried by analysts. Before 
executing a query on an identifier, the EAR verifies that the identifier is RAS-approved. If an analyst attempts to query a non-RAS-approved identifier while 
still in BR or PR/TT query mode, the EAR will provide reasonable assurance that no results are returned for that query: this includes data not derived from 
BR or PR/TT. This query will, how ever, be refle cted in SV's auditing and a justification for the query attempt may be requested. If you are unsure whether 
an identifier is RAS-approved, useB |to determine the identifier's approval status. 
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FRAME ID: 4077 
NEXT FRAME ID: 4080 

BACK FRAME ID: 4075 
ALT TAG: 
GRAPHIC/AV: 

(U) Image of OGC Attorney, HMC 
Character, and SV Character sitting at a 
table 

(U) Look at dm notes and match 
transcript to screen shots. 
(T5//5I//NF) Create animation to explain 
the following: While the BR Order permits 
contact chaining for up to three hops, NSA 
has decided to limit contact chaining to only 
two hops away from the RAS-approved 
identifier without prior approval from your 
Division management to chain the third 
hop. Under PR/TT, the FISC limits the 
number of hops for internet 
communications to only two, and the hop 
counter will not permit these FISC- 
mandated levels to be exceeded 


(TS//SI//NF) Contact Chaining with BR and PR/TT metadata 




(T5//5I//NF) (HMC Character): Once the EAR 


verifies that the seed that the analyst has requested to query is RAS approved, it will allow the analyst to 
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"chain" on that identifier. In the BR and PR/TT Orders, the FISC sets limits on how e xtensive this chaining may be. We refer to this as the number of hops 
from a RAS-approved identifier. For example, let's say your target calls an associate | ^That associate then calls several| |ln 

this example it is one hop from your RAS-ap proved id entifier to the associate and another hop from the associate to a recruit In other words, the associate 
is a "first hop" contact of your target and the I lare 'Second hop" contacts. 



( TS//5 I //NF ) (OGC Attorney): Whil e the BR Order permits contact chaining for up to three hops, NSA has decided to limit contact chaining to only tw o hop: 
away from the RAS-approved identifier without prior approval from your Division management to chain the third hop. Under PR/TT, the FISC limits the 
number of hops for internet communications to only two. Technical controls will not permit these F ISC-mandated hop levels to be exceeded. 



Comment [a5] : We can probably use some of the 
existingscreenshote we trade to also i 1 1 ustrate the 
hops. 



( TS//S I //NF ) (HMC Character): If another RAS-approved identifier is encountered within the authorized number of hops from the previous RAS-approved 
identifier, the number of hops resets to allow a contact chain to be generated out the authorized number of hops from the newly encountered RAS- 
approved identifier. 
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(TS//SI//NF ) What is a Query Result and how do I know if it is a BR or PR/TT Query 
Result? 

( TS//S I //NF ) Quer y Result: Queries produce results in the form of a contact chain 
presented in^^^bmnat; each chain is comprised of individual contacts derived from data 
returned from the multiple collection sources queried. Each contactyline within a chain 
represents an individual result 



( Comment [a6]: This is illustrated by screenshot 2 1 



( TS//S I //NF ) (HMC Character): When you query a RAS-approved identifier in I |n BR or PRATT modes, | g»ill return a ^^|file, usually 
referred to as a chain, which is made up of the individual first hop contacts of the seed. Bearing in mind the hop restrictions just discussed, analysts may do 
further chaining on those contacts. Each of these contacts, or line within the chain, represents an individual resul t Remember, unless you choose to 
unfederate your query as we described earlier, these results may have been obtained under a variety of collection authorities. 

( TS//5 I //NF ) It is possible to determine the collection source or sources of each result within the chain by examining the Producer Designator Digraph 
(PDDG)/SIGINT Activity Designator (SIGAD) and collection source(s) at the end o f the line. 



Comment [a7]: This is illustrated by screenshot 2 



( T5//5 I //NF ) If at least one source of a result is BR or PR/TT metadata, the classification at the beginning of the line will contain the ph rases FISABR or 
PR/TT, respectively. In addition, in the source information at the end of the line, the SIGAD ^^^B^^B^^^^^^^^^^^^^^^^^MSR d ata can be 
by SIGADs withB 

collected after October found H HFor a 

comprehensive listing of all the BR and PR/TT SIGADs as well as information on PR/TT data collected prior to November of 2009, contact your 



Comment [SLS8]: Notefor audio recording, this 
should be pronounced as a word "SIGAD" ( not 
spelled out in letters as S I G A D) 



Comment [a9]: I really think we need some 
For PR/TT, dato( pictures to illustrate 
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organization's management or subject matter expert 



(T5//3 1//N l~ ) Since it is possible that one communication event will be collected under multiple collection authorities (and multiple collection sources), not al 
of the results will be unique to one collection authority (or collection source). Keep in mind that the classification at the beginning of each result only 
indicates the highest level classification of that result, and does not necessarily reflect whetinei^yTesultwa^unicju^oonecollectior 
source). If a result was obt ained under multiple authorities (or sources), you will see morej 

I Here are examples of results originating from multiple collection sources. None of these results are considered BR- or PR /TT- 



|Comment [SLS10]: Notefor audio recording, 
the acronym PDDG should be spelled out in letters 
"P D D G" foil owed by the word "SI GAD" - so this 
phrase wi 1 1 be recorded as "Producer Desi gnator 
Digraph, or PDDG or SI GAD" 



Comment [all]; Screenshot 
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(TS//SI//NF ) What is a BR- or PR/TT-Unique Query Result? 

(U) (Insert image of OGC Attorney and HMC Character sitting at a table discussing the 
talking points below shown on a white board) 

( TS//S I //NF ) BR- or PR/TT-"unique" query results are those contacts within a chain 
solely derived from the BR or P R/TT metadata and not duplicated in the results originating 
from any other authorities. 



(T5//5 I //NF) (HMC Character): In the examples we just discussed, none of the results were unique to any one collection authority. Frequently, however, 
you'll find that some of the results within the chain are unique to one particular collection authority. A BR- or PR/TT-unique query result is any piece of 
information that NSA would not have had but for the BR or PR/TT metadata from which it was drawn. In other words, BR or PR/TT was the ONLY source of 
that individual contact/query result 



(TS//5 I //NF) Here are some examples: example A is "E.O. 12333-unique," while B is 'PR/TT-unique," and C is "BR-unique.' 



Comment [al2]: Againshow previous examples, j 



(TS//5 I //NF) Sharing restrictions in the FISC Orders only apply to unique BR or PR/TT query results. If query results are derived from multiple sources anc 
are not unique to BR and PR/TT alone, the rules governing the other collection authority would apply. We will discuss these sharing and handling 
restrictions in greater depth shortly. 



Comment [SLS13]: Note for audio recording: 
we will want sometime in between saying example 
A is "E.O. 12333-unique," and while B is 
"PR/TT-unique," and and C is "BR-unique." 

to allow learner to look at the examples. Please 
allow some "quiet' space that can be duplicated 
to the amountof time needed. THANKS! © 
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FRAME ID: 4100 


(TS//SI//NF) BR or PR/TT Query Results - Not J ust a Line Within a Chain 
(TS//SI//NF) Examples of BR and/or PR/TT Query Results include: 






NEXT FRAME ID: 4105 


• A specific identifier 

• 'Identifier A was in contact with Identifier B" 










• A .cml file (i.e. the entire contact chain/result set) that contains BR or PR/TT query 




BACK FRAME ID: 4090 


results 

• A written or electronic depiction of a chain (i.e., the .cml file itself) orthe analysis or 
partial analysis of a chain that includes BR or PR/TT results 

• A compilation or summary of first- and second-level contacts from a RAS-approved 




ALT TAG: 




GRAPHIC/AV: 






seed 












• A draft or a finished but not yet disseminated report 








• Any other BR or P R/TT information returned following a RAS-approved federated 






query 
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( TS//5 I //NF ) (OGC Attorney): Before we discuss sharing and handling restrictions of BR- and PR/TT-unique query results, it is impor tantto understand that 
a BR or PR/TT query result is not just a line within the chain that is presented to you after you run a BR or PR/TT query in| |Any information that 
you derive, extract, or manipulate from that particular line in the chain becomes a BR or PR/TT result Given that a source of the result is derived from BR 
or PR/TT metadata, any adaptation of that result, including information provided orally or in writing, even a tip or a lead, remains a BR or PR/TT query 
result 



( T5//5 I //NF ) (OGC Attorney): In addition, other examples of items that have been deemed to be BR and PR/TT query results include: 
A specific identifier 

'Identifier A was in contact with Identifier B" 

A ^^file (for example the entire contact chain/res ult se t) that contains BR or PR/TT query results 

A written or electronic depiction of a chain (like the ^^|file itself) or the analysis or partial analysis of a chain that includes BR or PR/TT results 
A compilation or summary of first- and second-level contacts of a RAS-approved seed 
A draft or a finished but not yet disseminated report 

Any other BR or PR/TT information returned following a RAS-approved federated query 



Comment [SLS14] : Note for audio recording, 
theSMEs would likeforttiis to be pronounced "the 
^|rile" I know this might sound a little odd 
sincewedon'tsaythingslike"thedotpdf file" but 
just trust me on this one because we had a 5 minute 
argument about it i n a SM E meed ng. UGH ! 

in 
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FRAME ID: 4105 


(TS//SI//NF) BR or PR/TT Query Results - Not J ust a Line Within a Chain 






NEXT FRAME ID: 4110 
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(T5//5I//NF) (HMC Character): So, for example, if you run a BR or PR/TT query on a particular RAS-approved e-mail identifier and it returns information 
that depicts identifier A, the RAS-approved seed, was in direct contact with identifier B and the source of the metadata is BR or PR/TT, then just the fact 
that identifier A is communicating with identifier B is considered a BR or PR/TT query result 

(TS//SI//NF) (HMC Character): In addition, any summary of that information would also be a BR or PR/TT query result So, if you knew that identifier A 
belonged to J oe and identifier B belonged to Sam, and the fact of that contact was derived from BR or P R/TT metadata, if you communicate orally or in 
writing thatj oe talked to Sam, even if you don't include the actual e-mail account or telephone numbers that were used to communicate, this is still a BR or 
PR/TT query result 

(TS//SI//NF) (OGC Attorney): Remember, if these results are determined to be BR- or PR/TT-UNIQUE, they are subject to sharinq and handlinq 
restrictions. 
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( TS//SI//NF ) Sharing and Handling Restrictions of BR- or PR/TT-Unique Query 
Results 

( TS//S I //NF ) Examples of handling restrictions for BR and PR/TT unique query 
results: 

• Any document, .cml, or other file containing BR- or PR/TT-unique information may 
only be stored on the analysts personal folders, or an access-controlled, shared 
location 

• Query results canr^^^^^^^^^^y system where the results would be shared with 

individuals without^ 

• BR- or PR/TT-unique results may not be queriecHritoolsvvhere user queries are 
visible to other analysts (who may not have| | or can be 

manipulated by behind the scenes analytics 



Comment [al5]: There is no such list of tools 
that are ok/ not ok to query, btw. 



(TS//SI//NF) These restrictions apply to information that is SOLELY unique to BR and 
PR/TT and do NOT apply to information which is NOT unique to BR or PR/TT! 



( TS//5 I //NF ) (OGC Attorney): Remember, BR- or PR/TT-unique query results are those contacts within a chain solely derived from the BR or PR/TT 
metadata and not duplicated in the results originating from any other authorities. Any oral or written depiction, manipulation, or summary containing that 
information is also a unique query result Until they are officially disseminated, BR- or PR/TT-unique results may only be shared with individuals who hold 
the proper credentials to receive or view BR or PR/TT information. The requirement is imposed because of the special handling restrictions that we will 
discuss later in this Module. Without the proper training, the F ISC-imposed handling restrictions may not be followed. 

( TS//S I //NF ) (HMC Character) Unless these unique results have been disseminated, such BR- or PR/TT-uniqueinforrnation may only be shared with 
individuals who have the proper credentials to receive or view BR or PR/TT information. Remember, use | |'- r> determine a user's credentials. Th' s 

means: 

« Any doc ument, ^M. or o ther file containing BR- or PRTT-unique information may only be stored on the analyst's personal folders, or an access- f Comment [SLS17]: pieasesay 



Comment [SLS161^Notefor audio recording, 
this is pronounced 
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or 



can be manipulated by behind the scenes analytics. If you have questions regarding which tools are acceptable to further research query results, 
please contact your management or technical director. 

( TS//S I //NF ) (SV Character) However, as we've discussed, not all BR or PR/TT results are unique. If a query result indicates it was derived from another 
collection source in addition to BR or PR/TT, the rules governing the other collection authority would apply to the handling and sharing of that query result 
For example, this result came from both BR and E.O. 12333 collection; therefore, because it is not unique to BR information, it would be ok to inform non- 
BR cleared individuals of the fact of this communication, as well as task, query, and report this information according to standard E.O. 12333 guidelines. 

( TS//5 I //NF ) (SV Character) In summary, if a query result has multiple collection authorities, analysts should source and/or report the non-BR or PR/TT 
version of that query result according to the rules governing the other authority. But if it is unique to either the BR or PR/TT authority then it is a unique 
query result with all of the applicable BR and PR/TT restrictions placed on it In both cases, however, analysts should not share the actual chain containing 
BR or PR/TT results with analysts who do not have the credentials to receive or view B R or PR/T T information. In such an instance, if it is necessary to 
share the chain, analysts should re-run the query in the non-BR or non-PR/TT areas of| | and share that .cml. 
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(U) Retention of Metadata and Query Results 

(TS//SI//NF) NSA must destroy BR and PR/TT metadata no later than five years (60 
months) after initial collection 

(TS//SI//NF) The FISC has not imposed any destruction requirement on BR or PR/TT 
query results 




(TS//5I//NF) (OGC Attorney): The Court Orders mandate destruction of the metadata five years or 60 months after initial collection. NSA destroys the BR 
and P R/TT metadata no later than five years after collection. There are no exceptions to this requirement when it comes to the bulk metadata. 

(TS//SI//NF) (HMC Character): The destruction requirement applies to the bulk metadata; it does not apply to query results that have been generated as a 
result of queries of RAS-approved identifiers. Once we have queried the metadata we have selected metadata, or query results, and the 60-month cutoff 
does not apply. 
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(U) Knowledge Check 2 

3. ( T5//S I //NF ) Please complete the following sentence. The Emphatic Access Restriction (EAR) 



a) createsar^utomarjc auditable record to allo w for oversight of these authorities. 

b) alerts | (when an individual without H (attempts to conduct a 
query. 

c) forwards the query request to the HMC for approval. ^^^^^^^^ 

d) prohibits non-RAS-approved identifiers from being queried in ( 

e) None of the above. 

4. ( TS//5 I //NF ) Assuming that the following answers describ^uniqueBF^orPR^T query results, which of the 
following could be shared with co-workers who do not havej 

a) Having a fellow analyst review the draft of a report that contains P R/TT-deri ved information 

b) A summary of direct or in direct contacts of a RAS- approved identifier 

your manager that( (contacted | ( as 

noted in the PR/TT query you recently performed 

d) E -mailing an electronic depiction of a BR or PR/TT contact chain or a pattern 

e) None of the above. 



5. (T5//5 I //NF) TRUE or FALSE: If a query result indicates that the source of information is both Executive 
Order 12333 collection and PR/TT collection, then the analyst must handle the E.O. 12333 result according 
to the PR/TT rules. 

a) True 

b) False 



(U) (HMC Character): Let's make a few notes in ourtravel journal and check to see what you remember from this topic! 
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ANSWERS: 

Question 3. ( TS//S I //NF ) Correct! The EAR prohibits non-RAS-approved identifiers from being queried in 
( TS//S I //NF ) Incorrect The correct answer is d). The EAR prohibits non-RAS-approved identifiers from being queried in 



Question 4. ( TS//S I //NF ) Correct! None of the examples listed should be shared with anyone outside of 
( TS//S I //NF ) Incorrect. The correct answer is e). None of the examples listed should be shared with anyone outside of 




channels. 



Question 5. ( TS//S I //NF ) Correct! If a PR/TT query result can also be sourced to Executive Order 12333, then the information is considered E.O. 12333 
collection and follows the E.O. 12333 processes and procedures. 

( TS//S I //NF ) Incorrect. If a PR/TT query result can also be sourced to Executive Order 12333, then the information is considered E.O. 12333 collection and 
follows the E.O. 12333 processes and procedures. 
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(U) Knowledge Check 2 

6 . (TG//5 I //ND I f! 




is your RAS-approved identifie r, and he e-mails 
who then e-mails | Hwho then e-mails 

how many hops is I H from your RAS-approved 




identifier? Are you allowed to chain that far in the PR/TT mode of 



a) 4 hops, no, unless one of the contacts between^ Jancl I l' s RAS 

approved. 

b) 3 hops, no (unless one of the contacts between j 
RAS approved). 

c) 4 hops, yes. 

d) 3 hops, no. 

e) 2 hops, yes. 



7. ( T5//5 I //NF ) If Badguyl's identifier is RAS-approved, and he calls Associatel, who then calls 
Unknownguy, who then calls Unknownguy2, how many hops jsJnknownguy2 from your RAS-approved 
identifier? Are you allowed to chain that far in the BR mode ol| 

a) 4 hops, no, unless one of the contacts between badguyl and unknownguy2 is RAS 
approved. 

b) 3 hops, yes (with management approval). 

c) 4 hops, yes. 

d) 3 hops, no. 

e) 2 hops, yes (with management approval). 
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ANSWERS: 

Question 6. ( TS//S I //NF ) Correct! The 
far unless one of the contacts between 
( TS//S I //NF ) Incorrect The correct answer is b). The 
permitted to chain this far unless one of the contacts' 

Question 7. ( TS//S I //NF ) Correct! The 
approval. ^ j 
( TS//S I //NF ) Incorrect. The correct answer is b). The 
management approval. ' 




is 3 hops from the RAS-appr oved identifier. You would not be permitted to chain this 
|is RAS approved. 

hop l S_fi22l52^£A^^2PI2 v ^^^ ent '^ er ■ ^ ou wou ' c ' not De 
His RAS approved. 

is 3 hops from the RAS-approved identifier. You are permitted to chain this far with management 
s 3 hops from the RAS-approved identifier. You are permitted to chain this far with 
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(TS//SI//NF) Dissemination of BR- and PR/TT- Derived Information 

(TS//SI//NF) Dissemination of BR and PR/TT results is distributing information to external 
customers in any form to include oral or written form 

(TS//SI//NF) Topics covered: 

• Information of foreign intelligence value which contains only foreign person information 
that IS NOT unique to BR or PR/TT 

• Information on U.S. persons (minimized) or foreign target activity unique to BR or PR/TT 
metadata 

• Information on U.S. persons (unminimized) unique to BR or PR/TT 


(TS//SI//NF) (OGC Attorney): Now lefs focus our attention on the dissemination of BR and PR/TT results. We define dissemination of BR and PR/TT 
results as distributing information to external customers in any form to include oral or written form. Lefs say you perform a BR or PR/TT query using a 
RAS-approved identifier, and the query returns good foreign intelligence information based on unique BR or PR/TT metadata that you would like to report 
to Intelligence Community customers. What should you do? In this topic we will discuss to what extent we can use standard processes and procedures for 
the dissemination of this information and to what extent we must use special processes and procedures for the dissemination of this special foreign 
intelligence information. Given the sensitive nature of this Program, you will not be surprised to hear that there are special rules that apply to the 
dissemination of this information. 
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(TS//SI//NF) Information Derived Exclusively from BR or PR/TT - Additional Requirements 



(TS//S I //NF) Standard reporting practices and policies (including sourcing requirements and 
procedures and USSID SP0018 minimization) apply to BR and PR/TT query results 

(TS//S I //NF) Two additional, BR- and PR/TT-specific requirements: 



The Counterterrorism (CT) nexus requirement applies to BR- and P R/TT-derived 
unminimized U.S. person information, but does notapplyto BR- or P R/TT-derived non- 
U.S. person information or BR- or P R/TT-derived minimized U.S. person information 
The dissemination tracking requirement applies to all BR- and P R/TT-derived 
information 



(TS//S I //NF) (OGC Attorney): First of all, every disseminated report from NSA must include sourcing information so that we know where the information 

came from, as well as follow all USSID SP0018 minimization requirements and procedures. For BR- and P R/TT-derived information, the analyst or r eport^ Comment [SLS18]: update 7/13/11 from the 
needs to make sure that the information included in that report is properly sourced to the appropriate BR or PR/TT authority. 



SM Es: PI ease record at U SSI D 18 (do not say SPEW 
or SPOW, just "USSID 18" 



(TS//S I //NF) In addition, the Court Orders for both the BR and PR/TT authorities have imposed two unique, stringent requirements with respect to 
disseminating information from these authorities. The first is the Counterterrorism, or CT, nexus requirement and the second is the dissemination tracking 
requirement 
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(TS//S I //NF) The CT Nexus Requirement 



( TS//S I //NF) Prior to the dissemination of BR- or P R/TT-derived unminimized U.S. person 
information outside of NSA, one of the designated approval authorities must determine: 

(a) that the U.S. person information is related to CT information, and 

(b) thatthe U.S. person information is necessary to understand the CT information 
or to assess its importance 



(TS//5 I //NF) (OGC Attorney): The CT nexus requirement applies only to U.S. person information. If you run a query and the information returned is all 
foreign person information, then the CT nexus requirement does not apply to this situation. However, if your query results include U.S. person information 
derived from BR or PR/TT and you want to disseminate that information to an external customer, such as the FBI, then this requirement must be met prior 
to dissemination, in any form. Traditionally, under USSID SPOOlgj , if there is a piece of unminimized U.S. person information that you would like to 
disseminate, one of the designated approval authorities (to be covered on the next screen) needs to determine that the information is necessary to 
understand the foreign intelligence in that particular intelligence report before the information can be released. For BR and PR/TT, the requirement is 
slightiy different 

(TS//S I //NF) (OGC Attorney): With respect to the BR and PR/TT authorities, the unminimized U.S. person information not only has to relate to and be 
necessary to understand the foreign intelligence information in the report, but it has to relate to and be necessary to understand the Counterterrorism 
information. 



Comment [SLS19]: update 7/13/11 from the 
SM Es: Please record at U SSI D 18 (do not say SPEW 
or SPOW, just "USSID 18" 
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(TS//5 I //NF) (HMC Character): Recall the RAS process and how you derived this information. The identifier you used to generate this information was 
^^jovj^^^^^oj^^^^^^j^gjj^^^^DUjd^o^^^^^ai|^r^reasonably believed to be used by someone | 

(T5//5 I //NF) (HMC Character): It might seem as though the information would most certainly be counterterrorism-related since, due to the RAS approval 
process, you wouldn't have this U.S. person information from a query of BR or PR/TT if it weren't related to counterterrorism. In the majority of cases, it will 
be counterterrorism-related; however, the nature of the counterterrorism target is that it often overlaps with several other areas that include 
countemarcotics, counterintelligence, money laundering, document forging, people and weapons trafficking, and other topics that are not CT-centric. Thus, 
due to the fact that these authorities provide NSA access to a high volume of U.S. person information for counterterrorism purposes, the Court Order 
requires an explicit finding that the information is in fact related to counterterrorism prior to dissemination. Therefore, one of the approved decision makers 
must document the finding using the proper terminology. It must state that the information is related to counterterrorism and that it is necessary to 
understand the counterterrorism information. 



(TS//S I //NF) (OGC Attorney): While the USSID SP0018 process is the most familiar method of governing the dissemination of unminimized U.S. person 
information obtained from traditional SIGINT means, the CT nexus requirement is an additional protection for U.S. person information being disseminated 
when the BR or PR/TT authorities, and metadata obtained by virtue of those authorities, is the source of the information. The FISC wants to ensure that the 
authorities are being used for counterterrorism purposes as intended, so consider the CT nexus requirement a step above justifying a foreign intelligence 
requirement 
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( TS//SI//NF ) Dissemination Approval Authorities 

( TS//S I //NF ) Only those in the following NS A positions have the authority to approve the 
dissemination of BR- or P R/TT-derived U.S. person(s) information: 

(U) USSID SP0018 

• (U //FOUO ) The Chief and Deputy Chief of Information Sharing Services 

• (U //FOUO ) The Senior Operations Officers (SOOs) of the National Security 
Operations Center (NSOC) 

• (U //FOUO ) The Director and Deputy Director of the Signals Intelligence Directorate 

• (U //FOUO ) The Director and Deputy Director of NSA 

(U) This approval authority cannot be delegated to anyone else! 



(T 5//5 I //NF ) (OGC Attorney): Certain positions are authorized to validate the CT nexus requirement, as we just discussed, and approve the dissemination 
of U.S. person(s) information that we obtain from these two authorities. 

( TS//5 I //NF ) (OGC Attorney): Recall from your USSID SP0018 training, there are certain positions at NSA which have the authority to approve the 
dissemination of information that would identify a U.S. person either by name or by context. Those positions are listed in USSID SP0018 and include the 
Chief and Deputy Chief of the Information Sharing Services Office, the Senior Operations Officers (SOO) within the National Security Operations Center 
(NSOC), the Director and Deputy Director of the Signals Intelligence Directorate (SID), and in some cases they include the Director and Deputy Director o 
NSA. 

( TS//S I //NF ) (HMC Character): The list of positions which can approve the dissemination of unminimized U.S. person information derived from unique BR 
and PR/TT query results is the same as those named in USSID SP0018. 



Comment [SLS20] : Note for audio recording, 
this is pronounced as a word "SOO" (rhymes with 
"new" , but does not rhyme with "sew a dress") 



Comment [SLS21] : Note for audio recording, 
this is pronounced "N sock" 
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( TS//5 I //NF ) (OGC Attorney): It is important to note that the authority to approve the dissemination of U.S. person information cannot be delegated. This 
responsibility is assigned only to the positions named in the BR and PR/TT Court Orders. Lefs say, for example, thatthe Chief and Deputy Chief of 
Information Sharing Services Office, the two individuals who on a normal daily basis would be making the decision, are both on vacation on the same day. 
In this instance, someone else within their office may be the acting chief on that day; however, the acting chief cannot make the decision to disseminate 
U.S. person information. 

( TS//S I //NF ) (HMC Character): Under these circumstances, if information about a U.S. person must be disseminated on that day, then you should send 
your dissemination request to one of the other positions named in the Orders. This would logically be the NSOC SOO. 

( TS//S I //NF ) (OGC Attorney): With respect to non-U. S. person information, standard NSA practices and policies (such as proper sourcing information) 

apply- 
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(U) Dissemination Tracking 

(TS//SI//NF) NSA must report to the FISC every 30 days the number of instances since the 
preceding report in which NSA disseminated BR- or P R/TT-derived information, in any 
form (oral, written, formal, or informal), with anyone outside of NSA 

(U) For more information, please contact | 


(TS//5I//NF) (OGC Attorney): The other requirement which applies to both U.S. person information as well as foreign person information, is trie 
dissemination tracking requirement regarding the dissemination of BR- and P R/TT-derived information. The Orders require NSA to track and report to trie 
FISC every instance in which NSA disseminates any information derived from either of these two authorities. 

(TS//SI//NF) (HMC Character): This refers to information disseminated in a formal report as well as information disseminated informally such as written or 
oral collaboration with the FBI. We need to count every instance in which we take a piece of information derived from either of these two authorities and 
disseminate it outside of NSA. 

(TS//SI//NF) (HMC Character): Normally an NSA product report is the record of a formal dissemination. In the context of the BR and PR/TT Programs, an 
official RFI response or Analyst Collaboration Record will also be viewed as dissemination. Because this FISC requirement goes beyond the more standard 
NSA procedures, additional diligence must be given to this requirement NSA is required to report disseminations formal or informal to the FISC every 30 
days. 
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(U) Post-Dissemination Restrictions? No, Restrictions lifted once Disseminated 

( TS//S I //NF ) Once approved for dissemination, BR- or P R/TT-derived information can be 
used within NSA for any lawful purpose, and the sharing restrictions no longer apply 
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(U) Possible cutaway images may include: 
• Image that portrays the lifting of the 
sharing restriction once information 
is approved for dissemination 

( TS//5 I //NF ) (OGC Attorney): Once BR and PR/TT information has been disseminated (such as in a product report, RFI, or briefing), generally speaking, 
there are no follow-on restrictions that either NSA or our customers need to follow regarding the sharing or dissemination of tfiat information contained in 
tfie report The Orders do not impose any restrictions on the use of formally reported information from the BR or PR/TT authorities: therefore, this 
information can be used for any lawful purpose. 



( T5//5 I //NF ) If BR- or P R/TT-derived information is disseminated outside of NSA, then the restrictions on internal sharing of that same information at NSA 



no longer apply. For ex 
other tools such as thel 



jsseminated can be shared outside of 



■channels, and the identifiers can be used in 
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(U) Knowledge Check 3 

8. (TS//SI//NF) Identify the additional requirements reqardinq the dissemination of unminimized U.S. person 
information derived from BR or PR/TT information: 

a. The Counterterrorism nexus check 

b. The Counterintelligence nexus check 

c. The dissemination tracking requirement 

d. The sourcing requirement 

e. Both a) and c) 

9. (TS//SI//NF) TRUE or FALSE: the dissemination tracking requirement applies to only U.S. person BR- or 
PR/TT-derived information. 

a. TRUE 

b. FALSE 


NEXT FRAME ID: 4210 
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ALT TAG: 


GRAPHIC/AV: 


(U) (OGC Attorney): Before we move on to th 


e next part of our trip, lefs make a few notes in our travel journal. 


ANSWERS: 

Question 8. (TS//SI//NF) Correct! The Court Orders for both the BR and PR/TT authorities have imposed two unique requirements with respect to 
disseminating information from these authorities. The first is the Counterterrorism, or CT, nexus check (which applies only to U.S. person information), and 
the second is the dissemination tracking requirement 

(TS//SI//NF) Incorrect, the correct answer is e). The Court Orders for both the BR and PR/TT authorities have imposed two unique requirements with 
respect to disseminating information from these authorities. The first is the Counterterrorism, or CT, nexus check (which applies only to U.S. person 
information), and the second is the dissemination tracking requirement. 

Question 9. (TS//SI//NF) Correct! The dissemination tracking requirement applies to both U.S. person and non-U. S. person BR- and PR/TT-derived 
information. 

(TS//SI//NF) Incorrect The dissemination tracking requirement applies to both U.S. person and non-U. S. person BR- and PR/TT-derived information. 
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refers to the distribution of 



10. ( T5//SI//NF ) Forthe purpose of the BR and PR/TT Programs 

information to customers in any form. is the provision of BR and PR/TT FISA query results with 

others inside of NSA authorized to receive BR and PR/TT query results. 

a) Dissemination, Distribution 

b) Sharing, Dissemination 

c) Dissemination, Sharing 

d) Sharing, Distributing 

11. ( TS//SI//NF ) Which one of the following NSA positions does not have the authority to approve the 
dissemination of BR- or P R/TT-derived unminimized U.S. person information? 

a) The SOOs in the NSOC 

b) The Director and Deputy Director of the Signals Intelligence Directorate 

c) The Director and Deputy Director of NSA 

d) The Office of General Counsel (OGC) 

e) The Chief and Deputy Chief of Information Sharing Services 



ANSWERS: 

Question 10. ( TS//S I //NF ) Correct! Dissemination is the more formal distribution of information to customers in either oral or written form. Sharing is the 
provision of BR and PR/TT FISA query results with others inside of NSA authorized to receive BR and PR/TT query results. 

( TS//S I //NF ) Incorrect The correct answer is c) Dissemination is the more formal distribution of information to external customers in either oral or written 
form. Sharing is the provision of BR and PR/TT FISA query results with others inside of NSA authorized to receive BR and PR/TT query results. 

Question 11. (TS//S I //NF) Correct! The answer is d) The OGC does not have the authority to approve the dissemination of BR- or P R/TT-derived unminized 
U.S. person information. 

(TS//S I //NF) Incorrect The answer is d) The OGC does not have the authority to approve the dissemination of BR- or PR/TT-derived unminized U.S. 
person information. 
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(U) Now that we have completed this part of your trip you should be able to: 

• ( TS//S I //NF ) Distinguish between the analysts authorized to query BR and PR/TT 
metadata and those authorized to view query results 

• ( TS//S I //NF ) Recognize the contact chaining restrictions for RAS-approved 
identifiers 

• ( TS//S I //NF ) Recognize what constitutes unique BR and PR/TT query results 

• ( TS//S I //NF ) Identify limitations that impact access, sharing, dissemination and 
retention of BR and PR/TT query results 

• ( TS//S I //NF ) Recognize the BR and PR/TT dissemination tracking requirement and 
the additional CT nexus requirement for U.S. person identifiers 



( TS//5 I //NF ) (OGC Attorney): Remember, you are responsible for ensuring that the recipient of query results is authorized to receive these results. Also, 
you must be mindful of the special restrictions for dissemination, either oral or written, of the BR- and P R/TT-derived information. 

(U) (OGC Attorney): Now that we have completed this part of the trip you should be able to: 

• ( TS//5 I //NF ) Distinguish between the analysts authorized to query BR and PR/TT metadata and those authorized to view query results 

• ( T5//5 I //NF ) Recognize the contact chaining restrictions for RAS-approved identifiers 

• ( TS//S I //NF ) Recognize what constitutes unique BR and PR/TT query results 

• ( TS//S I //NF ) Identify limitations that impact access, sharing, dissemination, and retention of BR and PR/TT query results 

• ( TS//S I //NF ) Recognize the BR and PR/TT dissemination tracking requirement and the additional CT nexus requirement for U.S. person identifiers 
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(U) This module will enable you to: 

• (U) Compare and contrast the analytical and technical work roles 

• (U) Identify analytical and technical personnel's authorization to touch the data 
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• (U) Identify how the authorities impact interactions with other roles and the data 
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(U) (Technical Character): During this part of our trip we will compare and contrast the analytical and technical work roles and provide you with a basic 
knowledge of the two distinct areas. This will serve as an introduction to the more role-specific module you will complete later. 


(U) This module will enable you to: 

• (U) Compare and contrast the analytical and technical work roles 

• (U) Identify analytical and technical personnel's authorization to touch the data 

• (U) Identify how the authorities impact interactions with other roles and the data 
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(U) The Analytical Work Role 

(TS//SI//NF) The Analytical Work Role includes these primary functions: 

• HMC 

• Those who conduct intelligence analysis queries 

• Those who can view and disseminate the results of intelligence analysis queries 


(TS//SI//NF) (HMC Character): The analytical work role includes three primary functions: Homeland Mission Coordinators (HMC), those who can conduct 
intelligence analysis queries, and those who can view and disseminate the results of intelligence analysis queries. 

(T5//5I//NF) Homeland Mission Coordinators, or HMCs, review and approve the RAS nominations. The analysts and HMCs work through the RAS approval 
process together to get the identifiers RAS-approved. 

(T5//5I//NF) Recall from the last module that not al^nalvstsarepemTitted to conduct contact chaining queries. Those who are permitted to conduct 
queries of the bulk metadata have been granted U ^credentials. Those who are permitted to view and disseminate query results, but 
not conduct queries, have been granted | (credentials. 
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(U) The Technical Work Role 

( TS//S I //NF ) The Technical Work Role is made up of tw o main functions: 

• Support to Collection and Metadata | 

• Support to Storage, Presentation, and Maintenance 
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( TS//S I //NF ) (Technical Character): The work performed by technical personnel in support of the Bulk Metadata Programs assists everyone working in 
support of these programs to maintain complia nce with ap plicable legal documents and relevant authorities. Within the technical roles, there are two main 
areas of responsibility: collection and metadata I Hand the storage, presentation, and maintenance of the metadata. 




(TS//G I //NT) Some high-level examples of how key organizations support collection and metadata ■ find ude: 

to gain access to BR and P R/TT metad ata. 
|develops protocol processing software that supports the collection and metadata^ |and standardization. 

• Mission Capabilities (TD) integrates the BR and PR/TT protocol processing software into the larger exploitation systems. 

( TS//S I //NF ) | (and Mission Capabilities also support the storage, presentation, and maintenance aspects of the Bulk Metadata 

Programs, and some high-level examples include: 

• Mission Capabilities manages the BR and PR/TT repositories, as well as prepares the metadata for the analysts to use. 

• | provides reasonable assurance that the data is normalized and presented in a usable format and provides support to 
intelligence analysts. 
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(U) Authorization to Touch the Data 

(U) Analytical and technical personnel have different authorization to touch the metadata 
due to the nature of their work roles 
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(U) Authorization for Analytical Personnel 

Perform intelligence analysis (querying the 



ALT TAG: 



GRAPHIC/AV: 

(U) Insert image of HMC Character and 
Technical Character sitting at a table 



(U) Authorizations for Technical Personnel 

Create, test, and im plement tools to make this 
data easier for analytic personnel to use (TS/( |) 
ValidateJha^aieaua|jd^^DDropriately control analyst's access 
■ (TG//G I // B B) Perform processes to make the data usable 

0 Validation 
0 Defeat of col lection 
0 Processing 

0 Analysis of high-volume identifiers 

0 Maintenance of records to demonstrate compliance 



( T5//5 I //NF ) (Technical Character): As we have discussed throughout the course, the sensitivity of the data drives many of the policies and restrictions that 
control access to the BR and PR/TT bulk metadata. However, because of the different roles and responsibilities of analytical and technical personnel, both 
have different authorizations to touch the metadata. Recall from Module 1 we defined 'touching the data" as any form of data handling that creates an 
opportunity for a violation of the FISC Orders to occur. These activities may include data acquisition, modifying/preparing the data, querying, viewing results 
of the queries, and even oversight and compliance functions. 



OVSC 1205 MS 5C 



A): 



( TS//5 I //NF ) (HMC Character): Analytic personnel have authorization to touch the metadata to perform intelligence analysis. Analyst actions, such as 
querying the metadata for intelligence analysis purposes, must be done in a controlled way via tools designed to limit intelligence analysis access to RAS- 
approved identifiers and to the appropriate number of hops. Using these tools also provides reasonable assurance that these queries are tracked and 
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audited. 



Technical Personnel Info (audio file name OVSC_1205_M5_5040_T): 

( TS//5 I //NF ) (Technical Character): Technical personnel create, test, and implement tools to make this data easier for analytic personnel to use, while 
validating that safeguards appropriately control analysts' access to the bulk metadata. Additionally, technical personnel may access the metadata to 
perform those processes needed to make the metadata usable for inteNiaenceana lysis. These processes may include metadata validation; the defeat 
of the collection, processing, or analysis of metadata associated with I I identifiers; and the maintenance of records to demonstrate 

compliance with the terms of the authority. 



(T G //G I //NTH i^rder to do this work effectively, technical personnel are allowed to access the metadata using identifiers that are not RAS-approvecHr^he 
case of JJ^J^JJ identifiers, technical personnel may use non-R AS -approved identifiers to query the metadata to confirm if the identifier is a| 

(identifier and thus should not be included for target analysis. They may then share the identifier and the fact that it is a | (identifier 

with authorized personnel. However, no other information resulting from such queries can be used for intelligence analysis purposes. 



( TS//S I //NF ) Technicah^ersonnel must take great care with their responsibilities because they may be accessing the data through tools that do not have 
safeguards, such as | |that impose restrictions and minimize the chances of a violation of the FISC Orders. As a result we need to maintain 
boundaries between technical and analytical personnel, and be crystal clear as to the circumstances under which the two groups can interact 
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(U) Interaction Between Analytical and Technical Personnel 

(U) (Begin with image of analytical and Technical Character sitting at a table, then provide a close up of the 
Technical Character) 

( T5//5 I //NF ) All interactions must be based on RAS-approved identifiers and those results found within the 
number of hops authorized for intelligence analysis purposes 
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( TS//S I //NF ) (Technical Character): As we just discussed, analytical and technical personnel have different authorizations to touch this metadata. 
Because of these differe nt authorizati ons, we must be careful when the two types of personnel are interacting with regard to this metadata. Specifically, 
outside of the sharing of | | identifiers for defeat purposes, technical personnel should only be providing analytical personnel information 

under certain conditions. 

( TS//S I //NF ) (HMC C haracter): Som etimes, when analyzing the results of intelligence analysis queries, one or more of the specific results may seem out 
of the ordinary. Is it a | | identifier that was overlooked? Is the identifier misnormalized? Is there something that just seems out of place? Or 

perhaps there is a particular data field in your results that you don't understand. In such instances, intelligence analysts may require assistance from 
certain technical personnel responsible for data integrity functions. 

( TS//S I //NF ) (Technical Character): In these instances, technical personnel may assist authorized intelligence analysts, but any and all assistance must 
be based on RAS-approved identifiers and those results found within the number of hops authorized for intelligence analysis purposes. Essentially, 
when providing information to analytical personnel in these circumstances, the technical personnel must abide by the rules for the analytical personnel. 

( TS//S I //NF ) (Technical Character): In the end, all personnel have a vested interest and shared responsibility in ensuring that only the most accurate 
intelligence information is reported to customers, while abiding by the policies and requirements in place for this metadata. 
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(U) Knowledge Check 

1. ( TS//5 I //NF ) TRUE or FALSE: Technical personnel and analytic work roles have the same authorization to 
touch the bulk metadata. 

a) TRUE 

b) FALSE 

2. ( TS//5 I //NF ) The Analytic Work Role includes these functions: intelligence analysts who query the data, 
intelligence analysts who can view the results of intelligence analysis queries, and . 

a) Mission Capabilities (TD) 

b) 

c) Homeland Mission Coordinators (HMC) 

d) j^^^^^^^^^^^^^ 

3. ( TS//S I //NF ) The Technical Work Roles are comprised of two general areas of responsibility including 1) 
and 2) _. 

|2) reviewing RAS nominations 



a) 1) collection and metadata I 

b) 1) collection of content, 2) storage, presentation, and maintenance of the metadata 

c) 1) reviewing RAS nominations, 2) working with the telecommunications partners 

2) storage, presentation, and maintenance of the 



d) 1) collection and metadata | 
metadata 



(U) 



(Technical Character): Let's make a few notes in our travel journal and see what we remember from this topic. 
ANSWERS: 

Question 1. ( TS//S I //NF ) Correct! The answer is b) FALSE. Technical personnel have authority to make the metadata usable for intelligence analysis, while 
analytical personnel can only touch the bulk metadata for intelligence analysis purposes using RAS-approved identifiers within the authorized number of 
hops. 

( TS//S I //NF ) Incorrect. The correct answer is b) FALSE. Technical personnel have authority to make the metadata usable for intelligence analysis, while 
analytical personnel can only touch the bulk metadata for intelligence analysis purposes using RAS-approved identifiers within the authorized number of 
hops. 
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Question 2. ( T5//S I //NF ) Correct! The correct answer is c). The Analytical Work Role includes analysts and Homeland Mission Coordinators (HMC). 
( TS//S I //NF ) Incorrect. The correct answer is c). The Analytical Work Role includes analysts and Homeland Mission Coordinators (HMC). 

Question 3. (TG//G I //NO Right! The correct answer is d). The Technical Work Roles are comprised of two general areas of support including collection and 
metadata | l as we 'l as storage, presentation, and maintenance of the metadata. 

(TS//SI//NF) Incorrect. The correct answer is d). The Technical Work Roles are comprised of two general areas of support including collection and 
metadata ^^^^^B as well as storage, presentation, and maintenance of the metadata. 
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(U) Knowledge Check 

4. (T5//SI//NF) staff have access to the bulk metadata in order to prepare the metadata for 
the analysts touse^^^^^^^^^ 

a) | 

b) Mission Capabilities (TD) 

c) Analytical 

d) Office of General Counsel (OGC) 

5. (TS//SI//NF) If an intelligence analyst seeks assistance from technical personnel, technical personnel 

a) can query the metadata to confirm the analyst's results and point out potentially noteworthy 
contacts at the third or fourth hop 


GRAPHIC/AV: 


b) should explain that they are unable to assist in any way, except to identify] 

identifiers 

c) may offer assistance, but must be cautious that any results shared or discussed are 
based on a RAS-approved identifiers and those results that fall within the number of hops 
authorized for intelligence analysis purposes 

d) should provide whatever assistance is needed, but make a note of it in case anyone in 
management has questions later 

e) should decline to assist because technical personnel should not assist intelligence analysts 


(No audio or transcript on this page) 


Question 4. (TS//5I//NF) Correct! Mission Capabilities staff has access to the bulk metadata in order to prepare the metadata for the analysts to use. 
(T5//5I//NF) Incorrect. The correct answer is b). Mission Capabilities staff has access to the bulk metadata in order to prepare the metadata for the analysis 
to use. 

Question 5. (TS//SI//NF) Correct! If an intelligence analyst seeks assistance from technical personnel, technical personnel may offer assistance, but 
must be cautious that any results shared or discussed are based on RAS-approved identifiers and those results that fall within the number of hops 
authorized for intelligence analysis purposes. 

(TS//SI//NF) Incorrect. The correct answer is c). If an intelligence analyst seeks assistance from technical personnel, technical personnel may offer 
assistance, but must be cautious that any results shared or discussed are based on RAS-approved identifiers and those results that fall within the 
number of hops authorized for intelligence analysis purposes. 
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(U) Summary 

(U) Now that you have completed this module you should be able to: 

• (U) Compare and contrast the analytical and technical work roles 

• (U) Identify analytical and technical personnel's authorization to touch the data 

• (U) Identify how the authorities impact interactions with other roles and the data 


(U) (Technical Character): Now that we have completed this part of our road trip, you should be able to: 

• (U) Compare and contrast the analytical and technical work roles 

• (U) Identify analytical and technical personnel's authorization to touch the data 

• (U) Identify how the authorities impact interactions with other roles and the data 

(TS//5I//NF) (Technical Character): Now that you are aware of the various roles that support the BR and PR/TT Programs you will move on to your role- 
specific module that will go into additional detail on topics relevant to your responsibilities. 
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(U) Module 6 

(U) The Analytical Work Role 

(U) This module will enable you to: 

• (TS//S I //NF) Identify how BR and P R/TT fit into the analytic workflow 

• (TS//S I //NF) Recognize how BR and PR/TT authorities apply to real-life scenarios 



ALT TAG: 
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( TS//5 I //NF ) (OGC Attorney): Throughout the first five modules of our course, we have discussed the BR and PR/TT Orders and the policies and 
procedures NSA has implemented to provide reasonable assurance of compliance with the Orders. We also have looked at the community of people and 
the work roles that are involved across the Enterprise to support that aspect of the mission. 



( TS//5 I //NF ) (HMC Character): This part of ourtrip is designed specifically for anyone working in an analytical role, or supervising staff in an analytical role, 
in support of the BR and PR/TT Bulk Metadata Programs. In particular we will discuss facets of BR and PR/TT that are of interest to analysts and HMCs. 
This module will enable you to: 

• ( T5//5 I //NF ) Identify how BR and PR/TT fit into the analytic workflow 

• ( T5//5 I // NF-) Recognize how BR and PR/TT authorities apply to real-life scenarios 
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( TS//S I //NF ) BR and PR/TT Programs enable NSA to fill collection gaps left by our other 
authorities 
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( TS//5 I //NF ) (Display introductory 
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story). 

( T5//5 I //NF ) Graphic showing the portfolio 
of CT authorities with BR and PR/TT 
highlighted. Possible video footage of the 
arrest. 

( TS//5 I //NF ) (HMC Character): In Module 1, we mentioned that in order to gain comprehensive insight into a target's activities, it is often necessary to 
leverage multiple authorities and tools. CT targets have maintained an ongoing desire to conduct attacks within the United States. Given the unique U.S.- 
focus of the BR and PR/TT Programs, NSA is able to fill collection gaps left by our other authorities. 

( TS//S I //NF ) To illustrate how these various authorities can complement each other to fill critical gaps, as well as to show how BR and PR/TT fit into the 
analytic workflow, we'll step through the example of Najibullah Zazi and the New York subway plot 
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( T5//5 I //NF ) (HMC Characte r): ^^^^^^^^^^^^^^^^^^^^^^^J, CT analysts discovered a Pakistan-based email address associated with^^^^Jj 

operations | | the 

tasked the address to FAA 702 and reviewed the subsequent traffic on a regular basis. 

( T5//5 I //NF ) In Fall of 2009, one particular piece of content collection obtained from FAA 702 revealed an email exchange between a Pakistan-based target 
and an unknown individual suggesting that an unspecified terrorist operation was about to take place. Within this email, the analyst also discovered what 
appeared to be a U.S. -based phone number that was missing the country |code^ 



Comment [al]: Graphic of 2 terrorists sending 
email to each ottier, show email indicating threat and 
contai ni ng a number without country code 
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NSA reported the suspicious activity and minimized U.S. phone number in a standard EGRAM. After 
receiving the unminimized U.S. phone number through NSA's Identity Release process, the FBI learned that the user of the unknown email address and 
owner of the phone number was a Colorado-based individual named Najibullah Zazi. FBI immediately started an investigation into Zazi's activities^ 
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( TS//S I //NF ) 




|U.S. person Na jibullah Zazi is the user of I 

| According to SIGINT reporting 
|a Pakistan-based al-Qa'ida (AQ) facilitator, 

Ireceived an email from Najibullah Zazi on 6 




Zazi also provided his 



Iphone number. 



( TS//5 I //NF ) (HMC Character): Simultaneously, to gain a fuller picture of Zazi's contacts, an NSA CT analyst submitted a RAS-approval reques t to an HMC 
on Zazi's phone number and email address. Recall from Module 3 that, in order to meet the RAS standard, an identifier must be tied to specific^ 

| In this case, the analyst met the RAS standardb^gasincnheiustificabon on the fact that Zazi was in direct 
communication with the Pakistan-based email address used by a member of ( (Because Zazi is a U.S. person, after the RAS 
requests on Zazi's identifiers were reviewed by an HMC, they were then sent to OGC, who performed a First Amendment review and gave the final 
lapprovaL 



( TS//S I //NF ) When considering RAS, analysts should remember to include just the basic facts needed with supporting documentation, as was done in the 
Zazi case, and not clutter the justification with excess information or documentation. 
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( TS//5 I //NF ) (HMC Character): After the RAS requests were approved, using the BR and PR/TT modes of B HCT analysts began running federated 
metadata queries on the approved identifiers, as we discussed in Module 4. The analyst querying Zaz^sCojoradoohone number discovered that around 
the time thatZazi exchanged emails with theHJ HJhe had also contactedB MJjhone numbers. Using the 

guidance that we discussed in Module 4, the analyst determined thatZazi's contacts with these (■■■■numbers were unique to BR metadata. Based on 

this uniqueness, the analyst began drafting a report in accordance with the dissemination guideli we reviewed in Module 4. Before the report was 

released, the Chief of S 12 determined that the report met the CT Nexus criteria and approved its release 1 ^ 



Comment [a5]: Use one of screanshots showing 
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(TS//5 I //NF) Remember, even 'Tact of statements describing whatBR- or PR/TT-unique data was discovered are considered "query results" underFISC 
guidelines an d must be handled in accordance with the Court Orders. However, once formally disseminated to customers, it no longer requires the 

Iprotection and is treated as normal SIGINT analysis, as is the case with the example we have just described. 
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(U) Knowledge Check 

1. ( T5//5 I //NF ) In the Zazi scenario, analysts used E.O. 12333 and FAA 702 collection to support RAS. 
Which source(s) can be used to support RAS? 

a) (U) FBI reporting 

b) (U) Open source information 

c) ( T5//5 I //NF ) NSA FISA collection 

d) (U) All the sources above can be used 

2. ( T5//5 I //NF ) Why was toe RAS request for Zazi sent to OGC for a F irst Amendment review? 

a) (TS//S I //NF) All RAS requests go to OGC for a First Amendment review 

b) (TS//S I //NF ) Zazi is a U.S. person 

c) (TS//SI//NF ) Zazi is a member of al-Qa'ida or an associated terrorist group 

d) ( TS//SI//NF ) The RAS determination was a close call 



(U) (HMC Character): Let's make a few notes inourtravel journal and check to see what you remember from tois topic! 



Question 1. (U //FOUO ) Correct! Any information that is lawfully in our possession may be used to support a RAS determination. 

(U //FOUO ) Incorrect, toe correct answer is d). Any information toat is lawfully in our possession may be used to support a RAS determination. 

Question 2. (U //FOUO ) Correct! A First Amendment review is only necessary when toe identifier is believed to belong to a U.S. person. 

(U //FOUO ) Incorrect toe correct answer is b). A First Amendment review is only necessary when the identifier is believed to belong to a U.S. person. 
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3) (TS//SI//NF) In this scenario, information was discovered that was unique to the BR authority. If that same 
information had also been discovered in E.O. 12333 collection, a CT Nexus determination would still need to 
be made in order to disseminate that information because the information was in the BR repository. 


NEXT FRAME ID: 6100 


a) (U)True 

b) (U) False 








4) (T5//5I//NF) Why are students without^ | allowed to learn that Zazi had contact with other New 
York numbers? ^^^^^^^^^^ 
a) (T5//5I//NF) That information is not specific enough to qualify as | 


BACK FRAME ID: 6080 


ALT TAG: 


b) (T5//5I//NF) The information is over one year old 

c) (TS//SI//MF) The information has been previously disseminated outside of NSA 




d) (TS//SI//NF) It is being shared for training purposes 




GRAPHIC/AV: 








(No audio or transcript on this page) 




Question 3. (T5//5I//NF) Correct! If the same information is discovered through another source, neither the BR nor PR/TT rules and requirements apply. 
(TS//SI//NF) Incorrect. The correct answer is b) (False). Neither the BR nor PR/TT rules and requirements apply if the same information is discovered 
through another source. 


Question 4. (TS//SI//NF) Correct! The information can be disclosed to those without | | because it has previously been disseminated outside 


of NSA. ^^^^^^^ 

(TS//5I//NF) Incorrect The correct answer is c). The information can be disclosed to those wiUiout| |only because it has previously been 


disseminated outside of NSA. 
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(U) Practice Scenario 1 

(T5//SI//NF) You are a| (cleared analyst who, through PR/TT metadata analysis of seeds associated 
with a high value CT target has identified a PR/TT-unique direct contact - email address^ 

believed to be used by someone iiTYemen^ouarenotsure whether the identifier warrants further development as 
a target, but to find out you place | | in a tasking database to enable content collection from 
E.O. 12333 sources. This tasking database is widely available to all intelligence analysts in the SIGINT Production 
Chain. For this reason, you note in the comments field thatthis identifier was discovered through metadata analysis 
and is believed to be a direct contact of the high value CT target, but you deliberately avoid identifying the P R/TT 
metadata as the source of the identifier. Are your actions in compliance with the terms of the PR/TT Orders? 

(U) Please select the your answer: 

a) (T5//5I//NF) Yes, because you did not include the reference to PR/TT. 

b) (TS//5I//NF) No, because you failed to mark the source of the identifier as PR/TT metadata. 

c) (T5//5I//NF) Yes, because the results will be governed under E.O. 12333 rules and procedures. 

d) (TS//SI//NF) No, because you have shared a PR/TT-unique quervresul^vith a wide audience 
of intelligence analysts, many of whom do not hold current M Hcredentials. 


(U) (HMC Character): Now lets practic 


e what we have learned using a real-life scenario. Carefully read the scenario and then select the best answer. 


ANSWER: 

a) (TS//SI//NF) Incorrect The correct answer is d). No, because you have shared a PR/TT-unique query result with a wide audience of intelligence 
analysts, many of whom do not hold current ( ^credentials. 

b) (TS//SI//NF) Incorrect The correct answer is d). No, because you have shared a PR/TT-unique query result with a wide audience of intelligence 
analysts, many of whom do not hold current | | credentials. 

c) (T5//5I//NF) Incorrect The correct answer is d). No, because you have shared a PR/TT-unique query result with a wide audience of intelligence 
analysts, many of whom do not hold current | | credentials. 

d) (TS//SI//MF) Correct! The right answer is d). No, because you have shared a PR/TT-unique query result with a wide audience of 
intelligence analysts, many of whom do not hold current | ^credentials. 
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(U //FOUO ) You should now be able to: 

• (TS//S I //NF ) Identify how BR and PR/TT fit into the analytic workflow 

• (TS//S I //NF ) Practice applying BR and PR/TT authorities in real-life scenarios 

(TS//S I//NF) If you have questions or wish to find out more, please contact yourj 
| leared manager or any of the following BR or PR/TT points of contact: 

OGC email alias: DL gc ops 
OGC Phone:| |or963-3121(s) 

OGC website: go GC 
HMCs email alias: DL CT HMC 

SID Oversight and Compliance email alias: DL SV42_all 



(U //FOUO ) (HMC Character): Now that we have completed this part of our road trip, you should be able to: 

• ( TS//S I //NF ) Identify how BR and PR/TT fit into the analytic workflow 

• ( TS//S I //NF ) Practice applying BR and PR/TT authorities in a real-life scenario 

( T5//5 I //NF ) (HMC Character): You are encouraged to reach out to youi'l (cleared manager or any of the points of contact listed here if you 

have any questions or if you want to find out more. Please remember that it is critical to our mission that we are 100% compliant with the requirements in 
the Court Orders especially with regards to collaborating, sharing, and disseminating this data through the course of your analysis work. You may review 
this course at any time and seek guidance from any of the points of contact listed here. 
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(U) PLEASE READ: Important Assessment Information 

• (U) You will view the questions in a separate Assessment Questions Document 

• (U) You will enter your responses in a separate QuestionMark online answer sheet 

• (U) You will have only one attempt to successfully complete the assessment 

• (U) Allow yourself sufficient time (approximately 30 minutes) to complete the assessment 

(U) To Complete the Assessment: 

• (U) Click the link to open the Assessment Questions Document 



(U) Go to the VUport SumTotal Content Player page, click on the Assessment link, and follow the 
instructions to complete the required exam 



Comment [SLS6]: Pleasemakethisalinkthat 
will open the Assessment Question pdf for 
Analytical Personnel (we will actually connect the 
link later). 



(U //FOUO ) (OGC Attorney): The final part of your trip will be to successfully complete the assessment for the course. Please be aware that for the 
assessment you will view the questions in a .pdf file and enter your responses in a separate QuestionMark online answer sheet Please be sure that you 
open the .pdf with the questions first before opening the QuestionMark online answer sheet You will have one attempt to complete the assessment Please 
allow yourself sufficient time (approximately 30 minutes) to complete the assessment 

(U //FOUO ) Please click the Assessment Questions Document link to open the .pdf question file and keep the window open. Then go to the VUport 
SumTotal Content Player page, click on the Assessment link on the left, and follow the instructions to complete the required exam. 
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(U) This module will enable you to: 
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- (TS//S I //N T ) - 1 dentify the various technical roles that support toe BR and PR/TT Bulk 
Metadata Programs 

(U) Identify toe responsibilities of each of toe technical roles 

(U) Recognize key points of the compliance certification process for mission 

systems and data flows 

( TS//S I //NF) P ractice applying BR and PR/TT authorities in real-life scenarios 
applicable to technical personnel 



(TG//G I //N r ) (OGC Attorney): During this part of our trip, we discuss several topics of particular interest to those of you in technical roles, or supervising 
staff in a technical role, supporting the BR and PR/TT Bulk Metadata Programs. It is important for you to remember that the essential support you provide 
enables all of the roles to perform their BR- and PR/TT-related work in compliance with applicable legal documents and relevant authorities. As we 
discussed in Module 5, because of this great responsibility, technical personnel have been given tremendous access to touch the data in order to make it 
available and usable for the analysts. 

(TS//5 I //MF ) (Technical Character): In this module we are going to discuss the authorizations, roles, and responsibilities of the Technical Personnel. This 
module will enable you to: 

• (TG//G I //NT) Identify the various technical roles that support the BR and PR/TT Bulk Metadata Programs 

Classified By: slsanc2 
Derived From: NSA/CSSM 1-52 
Dated: 20070108 
Declassify On: 20350501 
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• (U) Identify the responsibilities of each of the technical roles 

• (U) Recognize key points of the compliance certification process for mission systems and data flows 

• (T5//5I//NT) Practice applying BR and PR/TT authorities in real-life scenarios applicable to technical personnel 
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(T5//5I//MF) (Technical Character): In Module 5, we explained there are two major areas where technical support is providedfor the BR and PR/TT Bulk 
Metadata Programs. The first is the group of technical personnel who are responsible for the collection and metadata H process. The second is the 
group responsible for storage, presentation, and maintenance of the BR and PR/TT metadata. In the next few screens, we will describe in more detail these 
two main areas of responsibility. 
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(U) Collection and Metadata Extraction Support 




(U) Collection and Metadata 




(U) Mission C£*3atoilitj<E 



(U// rOUO) (Technical Character): Let's examine more closely the work roles res| 
category of technical staff currently includes the technical professionals in NSA's 




Mission 



Capabilities staff within the Technology Directorate (TD) organizations. As we proceed through this module you will find out more about the roles in each of 
these three organizations. 

(TG//G I //NT) Note that in addition to these key roles, there are other technical roles that are important to the implementation of these programs. These roles 
include individuals involved in the acquisition, processing, presentation, storage, retention, and support to operations which are authorized under the BR 
and PR/TT Orders. 
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Some of the rules that apply to Mission Capabilities staff within the Technology Directorate (TD) are to provide reasonable assurance that: 



m 



All of the metadata remains identifiable as PR/TT data 
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(U) Knowledge Check 1 

(U) Match the organization to its corresponding roles and responsibilities: 

1. (TS7 7?t#NEJ^taff in is responsible for developing th e I 

a) (U) Mission Capabilities 

b) I 

d) (U) Homeland Mission Coordinators 

is responsible for integrating the PR/TTl 
"Including conducting related testing prior to system 

a) (U) Mission Capabilities 

b) 




d) (U) Homeland Mission Coordinators 
3. (T5//G I //ND Staff in is responsible for] 




a) (U) Missio n Capabilities 
b) 
c) 

d) (U) Homeland Mission Coordinators 




(U) (Technical Character): Lefs make a few notes in ourtravel journal and check tD see what you remember from this topic! 
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(TG7/G I //Nr) (Technical Character): Now lefs discuss the work roles responsible for the storage, presentation, and 
metadata. This category of technical staff currently includes the technical professionals in Mission Capabilities and 



e BR and PR/TT 
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(TS//SI//NF) Mission Capabilities is 
responsiblefor: 

• Developing maintaining, and operating 
repositories that store and present BR and 
PR/TT metadata 




(T5//5 I //N r ) S ome of the rul es that appl y tjo Mission Capabilities: 

• M ebadata must be maintained in secure NSA repositories 

• Data must be identifiable as B R or PR/TT 

• I mpl ement techni cal control s to prevent unauthori zed access 

• Restrict intelligence analysis queries to RAS-approved identifiers (eg. the EAR) 

• E nsure i ntd I i gence anal ysi s queri es remai n wi thi n authori zed number of hops 

• Createauditable records of all intelligence analysis queries 

• Destroy al I metadata before the end of the f i ve year authori zed retenti on peri od ( no 
exceptions!) 

• Changes to systems must be certified by theTD Compl i ance Off i ce before 
implementation 

• Automated queries are prohibited without approval 
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(TS//S I //NE) (Technical Character): You will recall that Mission Capabilities supports collection and metadata 




and other branches of Mission 



Capabilities support storage, presentation, and maintenance of the metadata. For Jhelatten the staff is typically database management and user interface 



(TD//G I//N T ) Some of the rules that apply to Mission Capabilities include: 

• Metadata must be maintained in secure NSA repositories 

• Data items must be identifiable as BR or PR/TT metadata 

• Implement technical controls to prevent unauthorized access 

• Implement technical controls to restrict intelligence analysis queries to RAS-approved identifiers (e.g. the EAR) 

• Implement technical controls to provide reasonable assurance that the results of intelligence analysis queries remain within the authorized number 
of hops 

• Create auditable records of all intelligence analysis queries 

• Destroy all metadata before the end of the five year authorized retention period (no exceptions for backup data) 




(TS//S I //N E-)-This staff will come in contact with human intelligible BR and PR/TT metadata. 




|tfiat store and present BR and PR/TT metadata, as well as 
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(T S//SI//N F) Protocol Exploitation is 
responsiblefor: 

• Ensuring data is normalized and is 
presented in a usable for mat 

• Providing support tointel I igence analysts 



For B R , ■ H erf orms uni que f uncti ons i ncl udi ng: 

Normalizing 

Re/i ewi ng data to ensure records i ncl ude onl y data H 

Assist in ensuring that data to be presented to analysts will be in a usable format 

Providing operational support to intel I igence analysts; support is limited to RAS-approved identifiers 

wi thi n the authori zed number of hops 



laracter): As you for PRATT, ■ Bprovides support toH H f° r 

BR, ■ Bassists in ensuring accurate representation and integrity of the metadata. In this contex t M^M^M^M^MM performs both a 

tech uppoiting role for intelligence analysts. Because of this dual role, J | must apply the rules governing the specific 

function it is performing at the time. WhemjerfomTinc^aJechnical role, the technical rules apply which allow broader access to the data. However, when 
supporting the intelligence analyst theH I staff must operate within the same rules applicable to the intelligence analyst which are more 
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restrictive. 



US//SI//NI-) For BR, | 



| performs unique functions to include: 
Normalizing all of the disparate data formats ^^^^^^^^^^^^^^^^^^^H 

Reviewing the data to validate that the records include only data| 

Assist in ensuring that the data to be presented to the analysts will be in a usable format 

Providing operational support as necessary to intelligence analysts; support is limited to RAS-approved identifiers within the authorized number of 
hops 
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(U) Knowledge Check 2 

4. (T5//5I//NF) Which one of these is not one of the roles and responsibilities of the technical personnel? 

a) (U//FOUO) Manipulating and validating the metadata to make it usable for intelligence analysis 
purposes 

b) (T5//5I//NT) Developing new tools to support querying of BR and PR/TT metadata 

c) ( G //G I //REL) Running an intelligence analysis query using a RAS-approved identifier for an analyst 
who is experiencing problems recreating their query results 

d) (S//G I //RCL) R unning an intelligence analysis query using a non-RAS -approved identifier for 
an analyst who is experiencing problems recreating their query results 

e) (U) Both C and D 

5. (TS//5I//NF)| |jrovides support to the BR program by doing the following (check all 
that apply): ^^^^^^^^^^^^^^^^ 

a) (U) Normalizing all of the disparate data formats j^^^^^^^^^^^^^^^H 

b) (U) Reviewing the data to validate that the records include data I 



c) (U) Ensuring metadata is maintained in secure NSA repositories. 

d) (U) Assist in ensuring that the data to be presented to the analysts will be in a usable format 

e) (U) Destroy all metadata before the end of the five year authorized retention period (no exceptions 
for backup data 

f) (S//SI//REL) Providing operational support as necessary to intelligence analysts on RAS- 
approved identifiers within the authorized number of hops 



nt and user interface professionals in 



6. (TG//5 I //ND Database 
maintain, and operate the | Ht na t store and present BR and PR/TT metadata, and develop 
algorithms/processes that prepare, optimize, and characterize the metadata for analytic utilization. 

a) 

b) 

c) 

d) (U) Homeland Mission Coordinators 



develop, 



(U) (Technical Character): Lefs check what you remember from this topic! 



Question 4. (TS//S I //Nr) Correct! Running an intelligence analysis query using a non-RAS-approved identifier for an analyst who is experiencing problems 
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recreating their query results is not one of the roles and responsibilities of the technical personnel. 



(T5//GI//NO Incorrect The correct answer is d). Running an intelligence analysis query using a non-RAS-approved identifier for an analyst who is 
experiencing problems recreating their query results is not one of the roles and responsibilities of the technical personnel. 



Question 5. (TS//5I//NF) Correct! J ^provides support to the BR program by doing the following: 

a) (U) Normalizing all of the disparate data formats ^^^^^^^^^^^^^^^^^^^^^m 

b) (U) Reviewing the data to validate that the records include data | 

d) (U) Assist in ensuring that the data to be presented to the analysts will be in a usable format 

f) (S//SI//REL) Providing operational support as necessary to intelligence analysts on RAS-approved identifiers within the authorized 
number of hoo^^^^^^^^^ 
(TS//G I //NI~) Incorrect^ | provides support to the BR program by doing the following: 

a) (U) Normalizing all of the clisiiarate data formats ^^^^^^^^^^^^^^^^^^^^^h 

b) (U) Reviewing the data to validate that the records include data | 

d) (U) Assist in ensuring that the data to be presented to the analysts will be in a usable format 

f) (S//SI//REL) Providing operational support as necessary to intelligence analysts on RAS-approved identifiers within the authorized 
number of hops 

Question 6. (T0//G I //NO Correct! Database management and user interface professionals in Mission Capabilities develop, maintain, and operate 
^store and present BR and PR/TT metadata, and develop algorithms/processes that prepare, optimize, and characterize the metadatal 

(TC //□ I //r J r ) Incorrect The correct answer is a). Database management and user interface professionals in Mission Capabilities develop, maintain, and 
operate the^^^^^^Btha^tore_and present BR and PR/TT metadata, and develop algorithms/processes that prepare, optimize, and characterize the 
metadata 
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(U) The Compliance Certification Process 

(U//FOUO) Compliance certification is a mandatory check for all systems handling U.S. 
person or FISA data 

(U) Guidelines governing the certification process are maintained by theTD Compliance 
Office 

(U) Compliance should be integrated into the development process 


(T5//5 1//N r ) (Technical Character): Next we will discuss the compliance certification process used by technical personnel who develop mission 
technologies to include those supporting the BR and PR/TT Programs. Compliance certification is a mandatory check forall systems handling U.S. person 
or FISA data. Guidelines governing the certification process are maintained by the TD Compliance Office. This process supports compliance with the 
applicable laws and authorities and supports the NSA Way. The NSA Way is a unified framework for building large (or small), complex, primarily software 
systems that meet the diverse needs of NSA missions. An important point is that compliance should be integrated into the development process. 
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(U) The goal of the compliance certification process is to integrate compliance into the 
development phase 
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(TS//S I//N F ) (Technical Character): The goal of the compliance certification process is to integrate compliance into the development phase. The gates 
shown in the compliance process represent distinct requirements that must be satisfied in order to provide reasonable assurance of compliance. The 
architects of the new technology develop engineering documents to support these requirements. The TD certification group reviews the artifacts to verify 
the compliance process requirements are being met 



(T5//3 I //NT ) The compliance certification process begins by registering inl 
browser. Once registration is complete, you will receive a requirements pa 



I Access the site by typing 



(U//FtX4C0 Compliance is an ongoing process. Any change or update to previously certified software requires recerrj 
words, if you develop a modification or upgrade to the software, then you need to register the software modification in 
recertification process. 
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(T5//0I//Nr) Formal approval is required for all new and/or different BR and PR/TT systems. Under no circumstances can a change be made to a software 
system (even for testing purposes) without going through the compliance certification (or recertification) process. 
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(U//FOUO) The goal of dataflow governance is to provide reasonable assurance of 
accountability and compliance for NSA mission data as it moves throughout NSA systems 



(U//FOUO) Triggers for entering the dataflow governance process include (but are not 
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(T0//G I //NT) (Technical Character): The Collection Strategies and Requirements Center (CSRC) is responsible for dataflow governance, which provides 
reasonable assurance of accountability and compliance for NSA mission data as it moves throughout NSA systems. This is critical to protect the data, and 
when we are talking about volumes of U.S. person data you can understand why this is so important 

(T5//G I //Nr) The process begins by submitting a dataflow request (usually done by the system builder or access owner) for a new dataflow solution. Then 
some level of research is needed to determine tine type of request and associated needs. Once the requirements are determined, a new processing 
capability may be developed, or an existing flow may be reconfigured to meet the new requirement The solution must then be tested and obtain official 
sign-off at which time CSRC authorization to operate would be issued. 

(U/TF^SUOHiTCieiTeral^ricia^rsfo dataflow governance process include (but are not limited to): 

• Replacing an existing repository 

• Inserting a process or system into the flow 

• Adding a new mission element 

• Legacy migration (moving an existing unmanaged flow to a managed flow) 

(TS//G I //Nr) Formal approval is required for all new and/or different BR and PR/TT data flows. Under no circumstances can a change be made to a data 
flow (even for testing purposes) without going through the dataflow governance process. 

(U// FOUO) To find out more about the dataflow process, please refer to the Dataflow webpage by typing 'go dataflow' in your web browser. 
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(U) Knowledge Check 3 

7. (TG//G I //Nr) The compliance certification process for new systems is triggered by 



a) (U) Entering a ticket intoH 

b) (U//FOUO) Contacting NSA Way Team 

c) (U//FOUO) Entering the new software or system into | 

d) (U) All of trie above 

8. (TS//SI//N^^^^^yj^Jo^^m^^^^^^yje^on for entering the dataflow governance process? 

a) I 

b) (U) Replacing an existing repository 

c) (U) Inserting a process or system into trie flow 

d) (U) Modifying a bulk metadata query 

e) (U) Moving an existing unmanaged flow to a managed flow 

9. (T5//5I//NT) Before an analytic software upgrade is released on a system that handles BR or PR/TT data, 
the developers would need to in order to remain compliant 

a) (U) contact the CSRC and undergo conjjMancerecertrfication 

b) (U) register the software release inH Hand undergo compliance recerb'fication 

c) (U) obtain OGC approval ^^^^^^^^^^H 



d) (U) register your system with ODOC 



(U) (Technical Character): Lefs make a few notes in ourtravel journal and check to see what you remember from this topic! 




Correct! The compliance certification process for new systems is triggered by entering the new software or system in 
ct The correct answer is c). The compliance certification process for new systems is triggered by entering the new software or system in 

Question 8. (U//FQIJQj Correct! Modifying a bulk metadata query is not a reason for entering the dataflow governance process. 
(U#F-QUQJJncorrect. The correct answer is d). Modifying a bulk metadata query is not a reason for entering the dataflow governance process. 

Question 9. (U/ /FOUO) Correct! Beforear^nalvtic software upgrade is released on a system that handles BR or PR/TT data, the developers would need to 
register the software release in I Hand undergo compliance recertification in order to remain compliant. 

(U //rOUO ) Incorrect The correc^^^^^^^^ ^Before an analy tic software upgrade is released on a system that handles BR or PR/TT data, the developers 
would need to register the software release in HJIHJ^BBand undergo compliance recertification in order to remain compliant 
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(U) Practice Scenario 1 ^^^^^^^^H 

(T5//5 1 //N T ) You are one of the | | cleared technic^^^^^^^^^^ponsible for metadata management 

within NSA's metadata repositories. You are working with otherM M-cleared developers on new query 

processes and tools. You | |a set of properly marked recor y your team for development 

purposes from the P R/TT metadata. This set of P R/TT metadata records is stored on a physically isolated system 
within NSA's secure network and is accessible only to the members of your team. Are your actions in 
compliance with the terms of the PR/TT Orders? 

(U) Please select the BEST answer: 

a) (TS//0 l //Nr) Yes, because the PR/TT Orders explicitly authorize properly trained technical 
personnel to develop and test new technologies to be used with the PR/TT metadata. 

b) tT5//5l//Mr) No, because the PR/TT Orders prohibit the use of new query processes against any of 
the PR/TT metadata. ^^^^^^^^m 

c) (T3//3I//Nf") Yes, because the| |PR/TT metadata records still carry the unique 
markings and sof^^re^ontoolson the physically isolated system to restrict access to 
those records to| | cleared personnel. 

d) (U) None of the above are correct 



(U) (Technical Character): Now lets practice what we have learned using real-life scenarios. Carefully read the scenario and then select the best answer. 



ANSWER: 

a) (T5//SI//Nr) Incorrect This statement is accurate, but this is not what makes your actions compliant The correct answer is c). Yes, because the 

^^R/TT metadata records still carry the unique markings and software controls on the physically isolated system to restrict access to 
those records '"I Reared personnel. 

(TG//G I //ND Inco rrect The current Court Orders authorize NSA to develop new query processes. The correct answer is c). Yes, because the 

J R/TT metadata records still carry the unique markings and software controls on the physically isolated system to restrict access to 
those records to | (cleared personnel. ^^^^^^^^^^H 

c) ( I V/UI//NI ) Correct! The best answer is c). Yes, because thel HpR/TT metadatajgCQrdsstjM carry the unique markings and 
software controls on the physically isolated system to res trie e records tol H-cleared personnel. 

d) (TS//G I //Nr) Incorrect The correct answer is c). Yes, because toe^^^^^^^^^JpR/TTnTetexjaterecords still carry the unique markings and 
software controls on the physically isolated system to restrict access to those records to H H-cleared personnel. 
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(U) Practice Scenario 

(TG//G I //NT) Y ou are a I H-cleared developer of contact chaining analytic tools. Your 

management chain has requested a briefing to demonstrate your progress on the latest version of the tool. 
You provide the briefing, which includes screen shots of the tool and query results generated by the tool. Are 
your actions in compliance with the Orders? 

(U) Please selectthe BEST answer: 

a) (U/ /FOUO) No, unless all of those onvourdevetogmentteam and all those who 
attended your briefing held current! ^clearances. 

b) (U) No, because the Court Orders do not permit testing of tools under development using 
real data. 

c) (U) Yes, as long as the query results shared during the briefing are never used for 
intelligence analysis purposes. 

d) (U) None of the above are correct 



ANSWER: 

a) (U) Correct! This is the best answer. You cannot provide a demonstration unless all of the individuals who attended the briefing have 
completed the required training and received the necessary accesses. 

b) (U/7FQJ 4P) Incorrect Th e correct answer is a). No, unless all of those on your development team and all those who attended your briefing held 
current| ^clearances. 

c) (U//FT>WO^nconaec^The correct answer is a). No, unless all of those on your development team and all those who attended your briefing held 
current I Hclearances. 

d) (U//F*Q yQ) Incorrect Th e correct answer is a). No, unless all of those on your development team and all those who attended your briefing held 
current H ^clearances. 
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(U) Practice Scenario 3 

(TS//SI//MF1 You are one of theH M-cleared technical personnel responsible for metadata 

management within NSA's metadata repositories. You are responsible for the maintenance of backup 
systems and Continuity of Operations (COOP) planning and implementation. You have contro^ver the 
backup tapes that hold PR/TT metadata collected since the inception of the PR/TT authority J ^ In 
accordance with your COOP plans, you know that if a disaster strikes and NSA's online metadata 
repositories are destroyed, you could use these backup tapes to repopulate the repositories with PR/TT 
metadata. Although the backup tapes contain information older than five years, the processes you would 
employ to repopulate the online analytic metadata repositories would select only metadata collected within 
the last five years. Is your maintenance of backup tapes holding PR/TT metadata collected more than five 
years ago in compliance with the terms of the PR/TT Orders? 

(U) Please select the BEST answer: 

a) (TG7/5 l //NO Y es, because the older-than-five-years PR/TT metadata on the backup tapes 
will never be available for intelligence analysis purposes. 

b) (TS//SI//NF ) Yes, because the PR/TT Orders specifically authorize NSA to maintain backup 
tapes of the PR/TT metadata. 

c) (TS//S I //NF ) No, because the PR/TT Orders mandate the destruction of the PR/TT 
metadata no later than five years after its initial collection, with no exception for 
metadata on backup tapes. 

d) (U) None of the above are correct 



ANSWER: 

a) ( T0//0 l //Nr ) Incorrect The correct answer is c). No, because the PR/TT Orders mandate the destruction of the PR/TT metadata no later than five 
years after its initial collection, with no exception for metadata on backup tapes. This is different from other authorities, for example FAA 702 does 
not require the destruction of data in the archives. 

b) ( TG//G I //NF ) Incorrect The correct answer is c). No, because the PR/TT Orders mandate the destruction of the PR/TT metadata no later than five 
years after its initial collection, with no exception for metadata on backup tapes. 

c) (TS//SI//M F) Correct! This is the best answer. No, because the PR/TT Orders mandate the destruction of the PR/TT metadata no later than 
five years after its initial collection, with no exception for metadata on backup tapes. 

d) (TS//S I //NT) Incorrect The correct answer is c). No, because the PR/TT Orders mandate the destruction of the PR/TT metadata no later than five 
years after its initial collection, with no exception for metadata on backup tapes. 
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(U) Now that you have completed this module you should be able to: 

• (TG//5 I //NO Identify the various technical roles that support the BR and P R/TT Bulk 
Metadata Programs 

• (U) Identify the responsibilities of each of the technical roles 

• (U) Recognize key points of the compliance certification process for mission 
systems and data flows 

• (TG//G I //NO Practice applying BR and PR/TT authorities in real-life scenarios 
applicable to technical personnel 

(U// rOUO> If you have questions or wish to find out more, please contact your manager or 
any of the following BR orPR/TT points of contact: 

TD Compliance Office website: go td compliance 

email alias:| 

Phone: | 
OGC website: go GC 

Oversight and Compliance email alias: DL SV42_all 



(TG//G I //NO (Technical Character): As we stated earlier in the course, the bulk metadata includes sensitive data that must be protected accordingly. By 
nature of the kinds of technical support provided to the BR and PR/TT programs, technical personnel have the authority and unrestricted access to touch 
unminimized/unevaluated (or raw), and very sensitive data (that contains a lot of U.S. person identifiers). Remember, we need to maintain a clear 
distinction between the roles of technical and analytical personnel. All personnel are held to a high standard of integrity, but in your technical role you must 
be particularly cautious because the tools you work with do not provide the same safeguards as those tools used by the analytical personnel. 
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( TS//G I //Mr) In conclusion, it is your responsibility to keep the BR and PR/TT information within the confines of those who have the proper authorizations to 
touch and view the data. 

(U) Now that we have completed this part of our road trip, you should be able to: 

• ( TG//5 I //Pdl~ ) Identify the various technical roles that support the BR and PR/TT Bulk Metadata Programs 

• (U) Identify the responsibilities of each of the technical roles 

• (U) Recognize key points of the compliance certification process for mission systems and data flows 

• (TD//fj l //Nr) Practice applying BR and PR/TT authorities in real-life scenarios applicable to technical personnel 

(U) You are encouraged to reach out to your management or to any of the points of contact listed here if you have any questions or if you want to find out 
more. 
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(U) PLEASE READ: Important Assessment Information 

• (U) You will view the questions in a separate Assessment Questions Document 

• (U) You will enter your responses in a separate QuestionMark online answer sheet 

• (U) You will have only one attempt to successfully complete the assessment 

• (U) Allow yourself sufficient time (approximately 30 minutes) to complete the assessment 

(U) To Complete the Assessment: 

• (U) Click the link to open the Assessment Questions Document; 



(U) Go to the VUport SumTotal Content Player page, click on the Assessment link, and follow the 
instructions to complete the required exam 



Comment [SLS1]: Pleasemakethisalinktnat 
will open the Assessment Quest] on pdf for 
Analytical Personnel (we will actually connect the 
link later). 



(U //rOUO - ) (OGC Attorney): The final part of your trip will be to successfully complete the assessment for the course. Please be aware that for the 
assessment you will view the questions in a .pdf file and enter your responses in a separate QuestionMark online answer sheet Please be sure that you 
open the .pdf with the questions first before opening the QuestionMark online answer sheet You will have one attempt to complete the assessment Please 
allow yourself sufficient time (approximately 30 minutes) to complete the assessment 

(U/ /rOUO) Please click the Assessment Questions Document link to open the .pdf question file and keep the window open. Then go to the VUport 
SumTotal Content Player page, click on the Assessment link on the left and follow the instructions to complete the required exam. 
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